--------[ AIDA64 Extreme ]----------------------------------------------------------------------------------------------

                                                AIDA64 v5.70.3800/ru
                                        4.2.671-x64
                                      http://www.aida64.com/
                                               [ TRIAL VERSION ]
                                             ALEXANDER_PC
                                             
                                   Microsoft Windows 10 Pro 10.0.19045.2965
                                                  2023-07-19
                                                 22:02


--------[   ]----------------------------------------------------------------------------------------

    :
                                             ACPI   x64
                                     Microsoft Windows 10 Pro
                                       [ TRIAL VERSION ]
      Internet Explorer                                 11.789.19041.0
      Edge                                              44.19041.1266.0
      DirectX                                           DirectX 12.0
                                           ALEXANDER_PC
                                         
                                              [ TRIAL VERSION ]
       /                                       2023-07-19 / 22:02

     :
                                                   12-Core AMD Summit Ridge, 3700 MHz
                                          
                                    
                                         [ TRIAL VERSION ]
       BIOS                                          AMI (12/18/2019)
                                      (COM1)

    :
                                            NVIDIA GeForce RTX 3060  (12 )
                                            NVIDIA GeForce RTX 3060  (12 )
                                            NVIDIA GeForce RTX 3060  (12 )
                                            NVIDIA GeForce RTX 3060  (12 )
                                                 Dell E2216H (DP)  [21.5" LCD]  (XV9JN61LAAWS)
                                                   PnP [NoDB]  (CA7A472308845)

    :
                                         nVIDIA Unknown @  High Definition Audio (Microsoft) [10DE-228E] [NoDB]
                                         Realtek ALC892 @ AMD K17 - High Definition Audio Controller

     :
      IDE-                                      SATA AHCI
      IDE-                                      SATA AHCI
                                   ()
                                  NVM Express
                                      Samsung SSD 970 EVO 500GB  (465 )
      SMART-                         OK

    :
      C: (NTFS)                                         [ TRIAL VERSION ]
      Z: (NTFS)                                         365.1  (102.8  )
                                              [ TRIAL VERSION ]

    :
                                               HID
                                               HID
                                               HID
                                                    HID- 
                                                    HID- 

    :
        IP                                [ TRIAL VERSION ]
        MAC                               18-C0-4D-44-F2-23
                                          Realtek Gaming GbE Family Controller  (192. [ TRIAL VERSION ])

     :
                                                 Fax
                                                 HP LaserJet P1005
                                                 Microsoft Print to PDF
                                                 Microsoft XPS Document Writer
                                                 OneNote for Windows 10
                                                   OneNote 16
      USB-                                    CONEXANT USB AUDIO
      USB-                                    HyperX Quadcast
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                     USB 
      USB-                                     USB 
      USB-                                     USB 
      USB-                                     USB 

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   F51
      DMI                           Gigabyte Technology Co., Ltd.
      DMI                                        B450 AORUS ELITE
      DMI                                Default string
      DMI                         [ TRIAL VERSION ]
      DMI  UUID                                [ TRIAL VERSION ]
      DMI                    Gigabyte Technology Co., Ltd.
      DMI                                 B450 AORUS ELITE
      DMI                           x.x
      DMI                    [ TRIAL VERSION ]
      DMI                             Default string
      DMI                                    Default string
      DMI                             [ TRIAL VERSION ]
      DMI Asset-                                [ TRIAL VERSION ]
      DMI                                       Desktop Case


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 ALEXANDER_PC
      DNS               Alexander_PC
      DNS              
      DNS              Alexander_PC
     NetBIOS                 ALEXANDER_PC
      DNS               Alexander_PC
      DNS              
      DNS              Alexander_PC


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  F51
                                             12/18/2019
                                                  16 
       BIOS                                5.14
                                   Floppy Disk, Hard Disk, CD-ROM
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, ACPI, UEFI
                                   PCI, USB
                                       

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                 http://www.aida64.com/bios-updates

  [  ]

     :
                                           Gigabyte Technology Co., Ltd.
                                                 B450 AORUS ELITE
                                                  Default string
                                           [ TRIAL VERSION ]
      SKU#                                              Default string
                                               Default string
        ID                       [ TRIAL VERSION ]
                                           

  [   ]

      :
                                           Gigabyte Technology Co., Ltd.
                                                 B450 AORUS ELITE
                                                  x.x
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]

  [  ]

     :
                                           Default string
                                                  Default string
                                           [ TRIAL VERSION ]
                                            [ TRIAL VERSION ]
                                                
                                     
                               
                                  
                                   

  [  / AMD Ryzen 5 2600 Six-Core Processor ]

     :
                                           Advanced Micro Devices, Inc.
                                                  AMD Ryzen 5 2600 Six-Core Processor
                                           
                                            
                                          
                                          100 
                                     3900 
                                          3400 
                                                     Central Processor
                                       1.1 V
                                                  
                                              AM4
      HTT / CMP                                         2 / 6
                                             64-bit, Multi-Core, Multiple Hardware Threads, Execute Protection, Enhanced Virtualization, Power/Performance Control

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

  [ - / L1 - Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                         8-way Set-Associative
                                       576 
                                      576 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L1 - Cache

  [ - / L2 - Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                         8-way Set-Associative
                                       3072 
                                      3072 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L2 - Cache

  [ - / L3 - Cache ]

     :
                                                     Unified
                                                1 ns
                                                  
                                             Write-Back
                                         16-way Set-Associative
                                       16384 
                                      16384 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Multi-bit ECC
                                              L3 - Cache

  [   / System Memory ]

      :
                                               
                                     
                                         
      .                                  128 
                                        4

  [   / DIMM 0 ]

      :
      -                                       DIMM
                                                     DDR4
                                                     Synchronous, Unbuffered
                                                  8 
      .                                      3200 
                                          3200 
                                             64 
                                            64 
      Ranks                                             1
      .                                    1.200 V
      .                                   1.200 V
                                       1.200 V
                                              DIMM 0
                                                    P0 CHANNEL A
                                           Kingston
                                           2455012E
                                          KHX3200C16D4/8GX

  [   / DIMM 1 ]

      :
                                              DIMM 1
                                                    P0 CHANNEL A
                                           
                                           
                                          

  [   / DIMM 0 ]

      :
      -                                       DIMM
                                                     DDR4
                                                     Synchronous, Unbuffered
                                                  8 
      .                                      3200 
                                          3200 
                                             64 
                                            64 
      Ranks                                             1
      .                                    1.200 V
      .                                   1.200 V
                                       1.200 V
                                              DIMM 0
                                                    P0 CHANNEL B
                                           Kingston
                                           D1550185
                                          KHX3200C16D4/8GX

  [   / DIMM 1 ]

      :
                                              DIMM 1
                                                    P0 CHANNEL B
                                           
                                           
                                          

  [   / J10 ]

      :
                                       J10
                                                     PCI-E x16
                                           
                                        x16
                                                   

  [   / J3600 Pcie x8 slot ]

      :
                                       J3600 Pcie x8 slot
                                                     PCI-E x8
                                           
                                        x8
                                                   

  [   / J3707 Pcie x4 slot ]

      :
                                       J3707 Pcie x4 slot
                                                     PCI-E x4
                                        x4
                                                   

  [   / USB 3.0 ]

      :
                                                USB
                                   J1500
                                    
                                      USB 3.0
                                       USB

  [   / USB 3.0 ]

      :
                                                USB
                                   J1501
                                    
                                      USB 3.0
                                       USB

  [   / USB-C ]

      :
                                                USB
                                   J1502
                                    
                                      USB-C
                                       USB

  [   / USB 3.0 ]

      :
                                                USB
                                   J1503
                                    
                                      USB 3.0
                                       USB

  [   / USB 3.1 ]

      :
                                                USB
                                   J1504
                                    
                                      USB 3.1
                                       USB

  [   / Network ]

      :
                                                Network Port
                                   J1503
                                    
                                      
                                       RJ-45

  [   / Sata Express ]

      :
                                                SATA
                                   J1704
                                    SATA/SAS Plug Receptacle
                                      Sata Express
                                       

  [   / Sata Express ]

      :
                                                SATA
                                   J1705
                                    SATA/SAS Plug Receptacle
                                      Sata Express
                                       

  [   / iSATA ]

      :
                                                SATA
                                   J1701
                                    SATA/SAS Plug Receptacle
                                      iSATA
                                       

  [   / iSATA ]

      :
                                                SATA
                                   J1702
                                    SATA/SAS Plug Receptacle
                                      iSATA
                                       

  [   / iSATA ]

      :
                                                SATA
                                   J1703
                                    SATA/SAS Plug Receptacle
                                      iSATA
                                       

  [   / iSATA ]

      :
                                                SATA
                                   J1706
                                    SATA/SAS Plug Receptacle
                                      iSATA
                                       

  [   / HDMI ]

      :
                                                Video Port
                                   J1100
                                    
                                      HDMI
                                       

  [   / HDMI ]

      :
                                                Video Port
                                   J1101
                                    
                                      HDMI
                                       

  [   / DP ]

      :
                                                Video Port
                                   J1102
                                    
                                      DP
                                       

  [   / Front Audio ]

      :
                                                Audio Port
                                   J2100
                                    
                                      Front Audio
                                       Mini-jack (headphones)

  [   / Audio Jack ]

      :
                                                Audio Port
                                   J2101
                                    
                                      Audio Jack
                                       Mini-jack (headphones)

  [   / Sata Express ]

      :
                                                SATA
                                   J1700
                                    SATA/SAS Plug Receptacle
                                      Sata Express
                                       

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Video
                                                  

  [   / Broadcom 5762 ]

      :
                                                Broadcom 5762
                                                     Ethernet
                                                  
       /  /                        4 / 0 / 0

  [  ]

    :
      OEM String                                        Default string
      System Configuration Option                       Default string


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   12-Core AMD Summit Ridge
      Engineering Sample                                
        CPUID                                      AMD Ryzen 5 2600 Six-Core Processor
       CPUID                                      00800F82h

     :
                                               3711.3 MHz

     :
       L1                                        64  per core
       L1                                      [ TRIAL VERSION ]
       L2                                            512  per core  (On-Die, ECC, Full-Speed)
       L3                                            16 

      :
      ID                                  63-0100-000001-00101111-022718-Chipset$8A16BG08_BIOS DATE: 12/18/19 10:08:46 VER: 05.0000E
                                          

     BIOS:
       BIOS                                  12/18/2019
       BIOS                            07/27/21
      DMI  BIOS                                   F51


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[  ]-----------------------------------------------------------------------------------------------------

     :
                                              ITE IT8705F  (ISA A40h)

    :
                                          35 C  (95 F)
                                                      32 C  (90 F)
      Aux                                               32 C  (90 F)
      Samsung SSD 970 EVO 500GB                         [ TRIAL VERSION ]

    :
                                                      5947 RPM
                                         680 RPM

    :
                                                  1.664 V
      +2.5 V                                            2.704 V
      +3.3 V                                            2.704 V
      +5 V                                              4.543 V
      +12 V                                             [ TRIAL VERSION ]
      +5 V                                        3.683 V
       VBAT                                      2.176 V
      Debug Info F                                      E3 FF F8
      Debug Info T                                      32 35 32
      Debug Info V                                      69 A9 A9 A8 5B 4A 72 89 88


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   12-Core AMD Summit Ridge, 3700 MHz
                                        x86, x86-64, MMX, SSE, SSE2, SSE3, SSSE3, SSE4.1, SSE4.2, SSE4A, AVX, AVX2, FMA, AES, SHA
      Engineering Sample                                
       L1                                        64  per core
       L1                                      [ TRIAL VERSION ]
       L2                                            512  per core  (On-Die, ECC, Full-Speed)
       L3                                            16 

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/processors
                                     http://www.aida64.com/driver-updates

    Multi CPU:
      CPU #1                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #2                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #3                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #4                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #5                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #6                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #7                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #8                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #9                                            AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #10                                           AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #11                                           AMD Ryzen 5 2600 Six-Core Processor, 3394 
      CPU #12                                           AMD Ryzen 5 2600 Six-Core Processor, 3394 

     :
       1 /  1                                     0%
       1 /  2                                     0%
       1 /  3                                     0%
       1 /  4                                     0%
       1 /  5                                     0%
       1 /  6                                     0%
       1 /  7                                     0%
       1 /  8                                     0%
       1 /  9                                     0%
       1 /  10                                    0%
       1 /  11                                    0%
       1 /  12                                    0%


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD Ryzen 5 2600 Six-Core Processor
       CPUID                                      00800F82h
        CPUID                          00800F82h
                                  D1h  (Socket AM4)
                               0800820Dh
      HTT / CMP                                         0 / 12

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                         
      AMD 3DNow! Professional                            
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                                
      AMD Extended MMX                                  
      AMD FMA4                                           
      AMD MisAligned SSE                                
      AMD SSE4A                                         
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Enhanced REP MOVSB/STOSB                           
      Float-16 Conversion Instructions                  , 
      IA-64                                              
      IA AES Extensions                                 
      IA AVX                                            , 
      IA AVX2                                           , 
      IA AVX-512 (AVX512F)                               
      IA AVX-512 52-bit Integer Instructions (AVX512IFMA52) 
      IA AVX-512 Byte and Word Instructions (AVX512BW)   
      IA AVX-512 Conflict Detection Instructions (AVX512CD) 
      IA AVX-512 Doubleword and Quadword Instructions (AVX512DQ) 
      IA AVX-512 Exponential and Reciprocal Instructions (AVX512ER) 
      IA AVX-512 Prefetch Instructions (AVX512PF)        
      IA AVX-512 Vector Bit Manipulation Instructions (AVX512VBMI) 
      IA AVX-512 Vector Length Extensions (AVX512VL)     
      IA BMI1                                           
      IA BMI2                                           
      IA FMA                                            , 
      IA MMX                                            
      IA SHA Extensions                                 
      IA SSE                                            
      IA SSE2                                           
      IA SSE3                                           
      IA Supplemental SSE3                              
      IA SSE4.1                                         
      IA SSE4.2                                         
      VIA Alternate Instruction Set                      
       ADCX / ADOX                            
       CLFLUSH                                
       CLFLUSHOPT                             
       CLWB                                    
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       INVPCID                                 
       LAHF / SAHF                            
       LZCNT                                  
       MONITOR / MWAIT                        
       MONITORX / MWAITX                      
       MOVBE                                  
       PCLMULQDQ                              
       PCOMMIT                                 
       POPCNT                                 
       PREFETCHWT1                             
       RDFSBASE / RDGSBASE / WRFSBASE / WRGSBASE
       RDRAND                                 
       RDSEED                                 
       RDTSCP                                 
       SKINIT / STGI                          
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
      Trailing Bit Manipulation Instructions             
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
      Hardware Random Number Generator (RNG)             
      Hardware Random Number Generator 2 (RNG2)          
      Memory Protection Extensions (MPX)                 
      PadLock Hash Engine (PHE)                          
      PadLock Hash Engine 2 (PHE2)                       
      PadLock Montgomery Multiplier (PMM)                
      PadLock Montgomery Multiplier 2 (PMM2)             
         (PSN)                    
      Protection Keys for User-Mode Pages (PKU)          
      Safer Mode Extensions (SMX)                        
      Software Guard Extensions (SGX)                    
      Supervisor Mode Access Prevention (SMAP)          
      Supervisor Mode Execution Protection (SMEP)       

     :
      Application Power Management (APM)                 
      Automatic Clock Control                            
      Configurable TDP (cTDP)                            
      Core C6 State (CC6)                                
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                               
      Hardware P-State Control                          
      Hardware Thermal Control (HTC)                     
      LongRun                                            
      LongRun Table Interface                            
      Overstress                                         
      Package C6 State (PC6)                             
      Parallax                                           
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                           
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitor 3                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                 

     :
      Extended Page Table (EPT)                          
      Hypervisor                                        
       INVEPT                                  
       INVVPID                                 
      Nested Paging (NPT, RVI)                          
      Secure Virtual Machine (SVM, Pacifica)            
      Virtual Machine Extensions (VMX, Vanderpool)       
      Virtual Processor ID (VPID)                        

     CPUID:
      1 GB Page Size                                    
      36-bit Page Size Extension                        
      64-bit DS Area                                     
      Adaptive Overclocking                              
      Address Region Registers (ARR)                     
      Code and Data Prioritization Technology (CDP)      
      Core Performance Boost (CPB)                      , 
      Core Performance Counters                         
      CPL Qualified Debug Store                          
      Data Breakpoint Extension                         
      Debug Trace Store                                  
      Debugging Extension                               
      Deprecated FPU CS and FPU DS                       
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Dynamic Configurable TDP (DcTDP)                   
      Extended APIC Register Space                      
      Fast Save & Restore                               
      Hardware Lock Elision (HLE)                        
      Hybrid Boost                                       
      Hyper-Threading Technology (HTT)                   
      Instruction Based Sampling                         
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      L2I Performance Counters                          
      Lightweight Profiling                              
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      NB Performance Counters                           
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event (PBE)                          
      Performance Time Stamp Counter (PTSC)              
      Physical Address Extension (PAE)                  
      Platform Quality of Service Enforcement (PQE)      
      Platform Quality of Service Monitoring (PQM)       
      Process Context Identifiers (PCID)                 
      Processor Feedback Interface                       
      Processor Trace (PT)                               
      Restricted Transactional Memory (RTM)              
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Mode Extension                            
      Watchdog Timer                                    
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                        
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States  
      XSAVEOPT                                          

    CPUID Registers (CPU #1):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-000C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000000-00000100-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-010C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000001-00000100-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-020C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000002-00000101-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #4):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-030C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000003-00000101-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #5):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-040C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000004-00000102-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #6):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-050C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000005-00000102-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #7):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-080C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000008-00000104-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #8):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-090C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    00000009-00000104-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #9):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-0A0C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    0000000A-00000105-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #10):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-0B0C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    0000000B-00000105-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #11):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-0C0C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    0000000C-00000106-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    CPUID Registers (CPU #12):
      CPUID 00000000                                    0000000D-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 00000001                                    00800F82-0D0C0800-7ED8320B-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000011
      CPUID 00000006                                    00000004-00000000-00000001-00000000
      CPUID 00000007                                    00000000-209C01A9-00000000-00000000
      CPUID 00000008                                    00000000-00000000-00000000-00000000
      CPUID 00000009                                    00000000-00000000-00000000-00000000
      CPUID 0000000A                                    00000000-00000000-00000000-00000000
      CPUID 0000000C                                    00000000-00000000-00000000-00000000
      CPUID 0000000D                                    00000007-00000340-00000340-00000000 [SL 00]
      CPUID 0000000D                                    0000000F-00000340-00000000-00000000 [SL 01]
      CPUID 0000000D                                    00000100-00000240-00000000-00000000 [SL 02]
      CPUID 80000000                                    8000001F-68747541-444D4163-69746E65 [AuthenticAMD]
      CPUID 80000001                                    00800F82-20000000-35C233FF-2FD3FBFF
      CPUID 80000002                                    20444D41-657A7952-2035206E-30303632 [AMD Ryzen 5 2600]
      CPUID 80000003                                    78695320-726F432D-72502065-7365636F [ Six-Core Proces]
      CPUID 80000004                                    20726F73-20202020-20202020-00202020 [sor            ]
      CPUID 80000005                                    FF40FF40-FF40FF40-20080140-40040140
      CPUID 80000006                                    26006400-66006400-02006140-00808140
      CPUID 80000007                                    00000000-0000001B-00000000-00006799
      CPUID 80000008                                    00003030-00001007-0000400B-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00008000-00000000-0001BCFF
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F040F040-00000000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    000003FF-00000000-00000000-00000000
      CPUID 8000001C                                    00000000-00000000-00000000-00000000
      CPUID 8000001D                                    00004121-01C0003F-0000003F-00000000 [SL 00]
      CPUID 8000001D                                    00004122-00C0003F-000000FF-00000000 [SL 01]
      CPUID 8000001D                                    00004143-01C0003F-000003FF-00000002 [SL 02]
      CPUID 8000001D                                    00014163-03C0003F-00001FFF-00000001 [SL 03]
      CPUID 8000001E                                    0000000D-00000106-00000000-00000000
      CPUID 8000001F                                    0000000F-0000016F-0000000F-00000000

    MSR Registers:
      CPB PStates                                       0
      CPU Clock (Normal)                                3751 MHz
      CPU Clock (TSC)                                   3394 MHz
      CPU Multiplier                                    0.0x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR 0000008B                                      0000-0000-0800-820D
      MSR C0010004                                      0000-0000-0D5A-FE06
      MSR C0010005                                      0000-0000-0000-0000
      MSR C0010006                                      0000-0000-0000-0000
      MSR C0010007                                      0000-0000-0000-0000
      MSR C0010015                                      0000-0000-0900-0011
      MSR C001001F                                      0000-0000-0000-0000
      MSR C0010055                                      0000-0000-0000-0000
      MSR C0010058                                      0000-0000-F800-0019
      MSR C0010061                                      0000-0000-0000-0020
      MSR C0010062                                      0000-0000-0000-0000
      MSR C0010063                                      0000-0000-0000-0000
      MSR C0010064                                      8000-0000-4890-8888 [x] [0.7000 V] [ 0.00 A] [PState P0]
      MSR C0010065                                      8000-0000-4719-CA8C [x] [0.2875 V] [ 0.00 A] [PState P1]
      MSR C0010066                                      8000-0000-43DD-107C [x] [1.4500 V] [ 0.00 A] [PState P2]
      MSR C0010067                                      0000-0000-0000-0000
      MSR C0010068                                      0000-0000-0000-0000
      MSR C0010069                                      0000-0000-0000-0000
      MSR C001006A                                      0000-0000-0000-0000
      MSR C001006B                                      0000-0000-0000-0000
      MSR C0010070                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010071                                      < FAILED >
      MSR C0010140                                      0000-0000-0000-0000
      MSR C0010141                                      0000-0000-0000-0000
      MSR C0011023                                      0002-2000-0000-0000


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  63-0100-000001-00101111-022718-Chipset$8A16BG08_BIOS DATE: 12/18/19 10:08:46 VER: 05.0000E
                                          


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   [ TRIAL VERSION ]
                                                  [ TRIAL VERSION ]
                                                8228 
                                                [ TRIAL VERSION ]

     :
                                                   21708 
                                                  12808 
                                                8901 
                                                59 %

     :
                                            C:\pagefile.sys
                                           5376 
      /                           229  / 482 
                                                4 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI EFI
       BIOS                                       F51
      UEFI Boot                                         
       BIOS                                  12/18/2019
       BIOS                            07/27/21

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                 http://www.aida64.com/bios-updates


--------[  ]----------------------------------------------------------------------------------------------------

    aida64.exe               C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe                    32         84544             53 
    ApplicationFrameHost.exe  C:\WINDOWS\system32\ApplicationFrameHost.exe                                  64         31540             12 
    audiodg.exe              C:\WINDOWS\system32\AUDIODG.EXE                                               64         14864              8 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           139             89 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           242            473 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         54824             31 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         21056             15 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         63588             33 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           221            198 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         59240             37 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         46236             23 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         52560             33 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         23732             12 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         48724             22 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           106             53 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64            97             44 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           105             53 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         64104             52 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         68032             48 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64            93             42 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           298            260 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         29976             17 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           167            102 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           206            160 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           191            144 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           305            221 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           104             56 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         79288             52 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           113             67 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           221            177 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64            96             47 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           219            178 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64         89672             43 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64          8784              6 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           127             85 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64           108             56 
    chrome.exe               C:\Program Files\Google\Chrome\Application\chrome.exe                         64            99             55 
    CompPkgSrv.exe           C:\Windows\System32\CompPkgSrv.exe                                            64          8120              1 
    Configurator.Service.WindowsService.DNS.exe  C:\Program Files (x86)\DNSAddappter\Configurator.Service.WindowsService.DNS.exe  64         53784             90 
    conhost.exe              C:\WINDOWS\system32\conhost.exe                                               64          1556              6 
    Cortana.exe              C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_4.2204.13303.0_x64__8wekyb3d8bbwe\Cortana.exe  64         65356             72 
    csrss.exe                                                                                              64          5008              1 
    csrss.exe                                                                                              64          5408              3 
    ctfmon.exe               C:\WINDOWS\system32\ctfmon.exe                                                64         21856              4 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32         42524             17 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32         26076             12 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32            88             81 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32           253            255 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32         63460             13 
    Discord.exe              C:\Users\\AppData\Local\Discord\app-1.0.9015\Discord.exe             32         74008             50 
    dllhost.exe              C:\WINDOWS\system32\DllHost.exe                                               64         12540              5 
    dllhost.exe              C:\WINDOWS\system32\DllHost.exe                                               64          9860              2 
    dwm.exe                  C:\WINDOWS\system32\dwm.exe                                                   64         74060            150 
    explorer.exe             C:\WINDOWS\Explorer.EXE                                                       64           167            164 
    fontdrvhost.exe          C:\WINDOWS\system32\fontdrvhost.exe                                           64          2944              1 
    fontdrvhost.exe          C:\WINDOWS\system32\fontdrvhost.exe                                           64         40588              8 
    GameCheck.exe            Z:\Lesta\GameCheck RU\GameCheck.exe                                           64           222            168 
    GoogleCrashHandler.exe   C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler.exe        64          1108              1 
    GoogleCrashHandler64.exe  C:\Program Files (x86)\Google\Update\1.3.36.272\GoogleCrashHandler64.exe      64          1036              1 
    lgc.exe                  Z:\Lesta\GameCenter\lgc.exe                                                   32         69704             48 
    lgc_renderer_host.exe    Z:\Lesta\GameCenter\dlls\lgc_renderer_host.exe                                32         23100              7 
    lgc_renderer_host.exe    Z:\Lesta\GameCenter\dlls\lgc_renderer_host.exe                                32         86324             68 
    lgc_renderer_host.exe    Z:\Lesta\GameCenter\dlls\lgc_renderer_host.exe                                32         64364             56 
    Lightshot.exe            C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe            32         16352             11 
    lsass.exe                C:\WINDOWS\system32\lsass.exe                                                 64         22348              8 
    Memory Compression                                                                                     64           367              1 
    Microsoft.Photos.exe     C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2023.10030.27002.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe  64          3064             96 
    MsMpEng.exe                                                                                            64           324            363 
    MusNotifyIcon.exe        C:\WINDOWS\system32\MusNotifyIcon.exe                                         64           928              3 
    NisSrv.exe                                                                                             64         13052              7 
    nvcontainer.exe          C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe               64         38688             12 
    nvcontainer.exe          C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe               64         27748              8 
    nvcontainer.exe          C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe               64         68384             72 
    NVDisplay.Container.exe  C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\Display.NvContainer\NVDisplay.Container.exe  64         19364              7 
    NVDisplay.Container.exe  C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\Display.NvContainer\NVDisplay.Container.exe  64         60140             49 
    NVIDIA Share.exe         C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe  64         66744             55 
    NVIDIA Share.exe         C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe  64         72544             82 
    NVIDIA Share.exe         C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe  64         45516             95 
    NVIDIA Web Helper.exe    C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe        32         13388             32 
    nvsphelper64.exe         C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe               64         12140              2 
    PhoneExperienceHost.exe  C:\Program Files\WindowsApps\Microsoft.YourPhone_1.23052.122.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe  64           124             95 
    Registry                                                                                               64         89760              6 
    RtkAudUService64.exe     C:\Windows\System32\RtkAudUService64.exe                                      64          7912              1 
    RtkAudUService64.exe     C:\WINDOWS\System32\RtkAudUService64.exe                                      64          9016              2 
    rundll32.exe             C:\WINDOWS\system32\rundll32.exe                                              64          7076              1 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         15604              2 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         27364              4 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64          7680              1 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         29732              9 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         25868              6 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         31120              8 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         21084              4 
    RuntimeBroker.exe        C:\Windows\System32\RuntimeBroker.exe                                         64         18464              3 
    SearchApp.exe            C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe    64           295            258 
    SearchFilterHost.exe     C:\WINDOWS\system32\SearchFilterHost.exe                                      64         11604              2 
    SearchIndexer.exe        C:\WINDOWS\system32\SearchIndexer.exe                                         64         45396             45 
    SearchProtocolHost.exe   C:\WINDOWS\system32\SearchProtocolHost.exe                                    64          9148              1 
    SearchProtocolHost.exe   C:\WINDOWS\system32\SearchProtocolHost.exe                                    64         15356              2 
    SecurityHealthService.exe                                                                                64         15276              4 
    SecurityHealthSystray.exe  C:\Windows\System32\SecurityHealthSystray.exe                                 64          9032              1 
    services.exe                                                                                           64          9344              5 
    SgrmBroker.exe                                                                                         64          7536              5 
    ShellExperienceHost.exe  C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe  64         60028             61 
    sihost.exe               C:\WINDOWS\system32\sihost.exe                                                64         29644              7 
    smartscreen.exe          C:\Windows\System32\smartscreen.exe                                           64         28624             10 
    smss.exe                                                                                               64           796              1 
    splwow64.exe             C:\WINDOWS\splwow64.exe                                                       64          8316              1 
    spoolsv.exe              C:\WINDOWS\System32\spoolsv.exe                                               64         14048              5 
    StartMenuExperienceHost.exe  C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe  64         89056             74 
    steam.exe                Z:\Steam\steam.exe                                                            32         73052             64 
    steamservice.exe         C:\Program Files (x86)\Common Files\Steam\steamservice.exe                    32         14144              8 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64           618            790 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64           338             53 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64         13832              7 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64           121            209 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64         31656             17 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64         23080              9 
    steamwebhelper.exe       Z:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe                               64         60684             82 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         11040              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8152              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         15944              8 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8432              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8372              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         12892              4 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         13568              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          9580              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         11400              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         19148              6 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          4888              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         10752              4 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         11928              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          7040              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         15468              6 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          9092              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         13376              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         11668              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         11028              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          6100              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         15476             14 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8580              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          6740              4 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          7384              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         10604              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          9368              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          7208              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          5764              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         13764              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          6800              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8032              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          7388              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          7936              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8120              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         18288              9 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         18240              8 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8996              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         10112              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8728              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         15568              4 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          6016              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         11928              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8836              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         17544             11 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          7824              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         11860              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          5884              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         41492             34 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         27888             19 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         14240              4 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          6024              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         19204              4 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          9924              2 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          5272              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          5076              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          6548              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         12544              3 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          7540              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          8236              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64          7512              1 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         25216              9 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         18144              5 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         43656             10 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         17640              4 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         18184              3 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         29348             11 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         22488              5 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         11816              2 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64         18368              7 
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               64          7192              1 
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               64         26248              7 
    System Idle Process                                                                                                      8              0 
    System                                                                                                 64            40              0 
    SystemSettings.exe       C:\Windows\ImmersiveControlPanel\SystemSettings.exe                           64         47192             67 
    taskhostw.exe            C:\WINDOWS\system32\taskhostw.exe                                             64         18280              7 
    taskhostw.exe            C:\WINDOWS\system32\taskhostw.exe                                             64         16508              5 
    Telegram.exe             C:\Users\\AppData\Roaming\Telegram Desktop\Telegram.exe              64           102            384 
    TextInputHost.exe        C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe  64         47924             55 
    UserOOBEBroker.exe       C:\Windows\System32\oobe\UserOOBEBroker.exe                                   64         10160              2 
    Video.UI.exe             C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.22091.10041.0_x64__8wekyb3d8bbwe\Video.UI.exe  64         18388             63 
    wininit.exe                                                                                            64          6340              1 
    winlogon.exe             C:\WINDOWS\system32\winlogon.exe                                              64         11708              2 
    WinRAR.exe               C:\Program Files\WinRAR\WinRAR.exe                                            64         34044              8 
    WmiPrvSE.exe             C:\WINDOWS\system32\wbem\wmiprvse.exe                                         64         13404              4 
    WmiPrvSE.exe             C:\WINDOWS\system32\wbem\wmiprvse.exe                                         64         10420              2 
    wordpad.exe              C:\Program Files\Windows NT\Accessories\WORDPAD.EXE                           64         49088             15 
    WUDFHost.exe             C:\Windows\System32\WUDFHost.exe                                              64          5916              1 
    WUDFHost.exe             C:\Windows\System32\WUDFHost.exe                                              64          6640              1 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI- -                                   1394ohci.sys          10.0.19041.1                          
    3ware            3ware                                                                   3ware.sys             5.1.0.51                              
    acdrv            AC driver                                                               acdrv.sys             50.0.0.0                              
    ACPI              Microsoft ACPI                                                  ACPI.sys              10.0.19041.1741                       
    AcpiDev             ACPI                                                AcpiDev.sys           10.0.19041.1                          
    acpiex           Microsoft ACPIEx Driver                                                 acpiex.sys            10.0.19041.1                          
    acpipagr            ACPI                                      acpipagr.sys          10.0.19041.1                          
    AcpiPmi              ACPI                              acpipmi.sys           10.0.19041.1                          
    acpitime          ACPI Wake Alarm                                                 acpitime.sys          10.0.19041.1                          
    Acx01000         Acx01000                                                                Acx01000.sys          10.0.19041.1503                       
    ADP80XX          ADP80XX                                                                 ADP80XX.SYS           1.3.0.10769                           
    AFD                  Winsock                              afd.sys               10.0.19041.2846                       
    afunix           afunix                                                                  afunix.sys            10.0.19041.1865                       
    ahcache          Application Compatibility Cache                                         ahcache.sys           10.0.19041.928                        
    amdgpio2         AMD GPIO Client Driver                                                  amdgpio2.sys          2.2.0.124                             
    amdgpio3         AMD GPIO Client Driver                                                  amdgpio3.sys          2.0.1.0                               
    amdi2c             I2C AMD                                              amdi2c.sys            1.2.0.99                              
    AmdK8            AMD K8                                                 amdk8.sys             10.0.19041.2728                       
    AMDPCIDev        AMD PCI                                                                 AMDPCIDev.sys         1.0.0.74                              
    AmdPPM             AMD                                                  amdppm.sys            10.0.19041.2728                       
    amdpsp           AMD PSP Service                                                         amdpsp.sys            4.11.0.0                              
    amdsata          amdsata                                                                 amdsata.sys           1.1.3.277                             
    amdsbs           amdsbs                                                                  amdsbs.sys            3.7.1540.43                           
    amdxata          amdxata                                                                 amdxata.sys           1.1.3.277                             
    AppID             AppID                                                           appid.sys             10.0.19041.2673                       
    applockerfltr      Smartlocker                                             applockerfltr.sys     10.0.19041.2673                       
    AppvStrm         AppvStrm                                                                AppvStrm.sys          10.0.19041.2673            
    AppvVemgr        AppvVemgr                                                               AppvVemgr.sys         10.0.19041.2673            
    AppvVfs          AppvVfs                                                                 AppvVfs.sys           10.0.19041.2673            
    arcsas           Adaptec SAS/SATA-II RAID -   Storport                   arcsas.sys            7.5.0.32048                           
    AsyncMac            RAS                                       asyncmac.sys          10.0.19041.1                          
    atapi             IDE                                                               atapi.sys             10.0.19041.1889                       
    atvi-randgrid    atvi-randgrid                                                           randgrid.sys          1.1.0.0                               
    b06bdrv            VBD QLogic                                              bxvbda.sys            7.12.31.105                           
    bam              Background Activity Moderator Driver                                    bam.sys               10.0.19041.1                          
    BasicDisplay     BasicDisplay                                                            BasicDisplay.sys      10.0.19041.1949                       
    BasicRender      BasicRender                                                             BasicRender.sys       10.0.19041.2006                       
    bcmfn2           bcmfn2 Service                                                          bcmfn2.sys            6.3.9600.17336                        
    Beep             Beep                                                                                                                                
    bindflt          Windows Bind Filter Driver                                              bindflt.sys           10.0.19041.2486            
    bowser                                                                            bowser.sys            10.0.19041.1586            
    BthA2dp          Microsoft Bluetooth A2dp driver                                         BthA2dp.sys           10.0.19041.1                          
    BthEnum            Bluetooth                                          BthEnum.sys           10.0.19041.2965                       
    BthHFEnum           Microsoft Bluetooth                           bthhfenum.sys         10.0.19041.1                          
    BthLEEnum         Bluetooth                              Microsoft.Bluetooth.Legacy.LEEnumerator.sys  10.0.19041.488                        
    BthMini            Bluetooth                                                 BTHMINI.sys           10.0.19041.2965                       
    BTHMODEM           Bluetooth-                                          bthmodem.sys          10.0.19041.1                          
    BTHPORT            Bluetooth                                                 BTHport.sys           10.0.19041.2965                       
    BTHUSB             USB  Bluetooth                                 BTHUSB.sys            10.0.19041.2965                       
    bttflt            Microsoft Hyper-V VHDPMEM BTT                                    bttflt.sys            10.0.19041.1                          
    buttonconverter                             buttonconverter.sys   10.0.19041.1                          
    CAD                                                       CAD.sys               10.0.19041.1                          
    cdfs             CD/DVD File System Reader                                               cdfs.sys              10.0.19041.2130            
    cdrom             CD-ROM                                                 cdrom.sys             10.0.19041.1266                       
    cht4iscsi        cht4iscsi                                                               cht4sx64.sys          6.11.4.100                            
    cht4vbd             Chelsio                                        cht4vx64.sys          6.11.4.100                            
    CimFS            CimFS                                                                                                                    
    circlass          -                                           circlass.sys          10.0.19041.1                          
    CldFlt           Windows Cloud Files Filter Driver                                       cldflt.sys            10.0.19041.2546            
    CLFS             Common Log (CLFS)                                                       CLFS.sys              10.0.19041.2913                       
    CmBatt              ACPI- ()                         CmBatt.sys            10.0.19041.1                          
    CNG              CNG                                                                     cng.sys               10.0.19041.2846                       
    cnghwassist      CNG Hardware Assist algorithm provider                                  cnghwassist.sys       10.0.19041.1                          
    CompositeBus                                          CompositeBus.sys      10.0.19041.1                          
    condrv           Console Driver                                                          condrv.sys            10.0.19041.1110                       
    CSC                                                               csc.sys               10.0.19041.1949                       
    dam              Desktop Activity Moderator Driver                                       dam.sys               10.0.19041.1052                       
    Dfsc                 DFS                                   dfsc.sys              10.0.19041.2604            
    disk                                                                         disk.sys              10.0.19041.1865                       
    dmvsc            dmvsc                                                                   dmvsc.sys             10.0.19041.1                          
    drmkaud                                                 drmkaud.sys           10.0.19041.746                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           10.0.19041.2913                       
    ebdrv             QLogic 10 Gigabit Ethernet VBD                                  evbda.sys             7.13.65.105                           
    EhStorClass      Enhanced Storage Filter Driver                                          EhStorClass.sys       10.0.19041.964                        
    EhStorTcgDrv         ,   IEEE 1667  TCG  EhStorTcgDrv.sys      10.0.19041.1                          
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            10.0.19041.1                          
    exfat            exFAT File System Driver                                                                                                 
    FACEIT           FACEIT                                                                  FACEIT.sys                                                  
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               10.0.19041.1                          
    FileCrypt        FileCrypt                                                               filecrypt.sys         10.0.19041.1               
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          10.0.19041.1               
    Filetrace        Filetrace                                                               filetrace.sys         10.0.19041.1               
    flpydisk                                                     flpydisk.sys          10.0.19041.1                          
    FltMgr                                                                  fltmgr.sys            10.0.19041.2788            
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         10.0.19041.2311            
    fvevol               BitLocker                              fvevol.sys            10.0.19041.1949                       
    gencounter         Microsoft Hyper-V                                      vmgencounter.sys      10.0.19041.1                          
    genericusbfn        USB                                                 genericusbfn.sys      10.0.19041.1                          
    GPIOClx0101      Microsoft GPIO Class Extension Driver                                   msgpioclx.sys         10.0.19041.488                        
    GpuEnergyDrv     GPU Energy Driver                                                       gpuenergydrv.sys      10.0.19041.1                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           10.0.19041.264                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          10.0.19041.2546                       
    HidBatt             HID                                                 HidBatt.sys           10.0.19041.1                          
    HidBth           Microsoft Bluetooth HID                                         hidbth.sys            10.0.19041.423                        
    hidi2c              HID-   I2C ()            hidi2c.sys            10.0.19041.1                          
    hidinterrupt         HID,                    hidinterrupt.sys      10.0.19041.1                          
    HidIr             Microsoft Infrared HID                                          hidir.sys             10.0.19041.1                          
    hidspi              HID- SPI Microsoft                       hidspi.sys            10.0.19041.1                          
    HidUsb             HID Microsoft                                            hidusb.sys            10.0.19041.2486                       
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            8.0.4.0                               
    HTTP             HTTP-                                                             HTTP.sys              10.0.19041.2728                       
    hvcrash          hvcrash                                                                 hvcrash.sys           10.0.19041.1                          
    hvservice        Hypervisor/Virtual Machine Support Driver                               hvservice.sys         10.0.19041.2728                       
    HwNClx0101       Microsoft Hardware Notifications Class Extension Driver                 mshwnclx.sys          10.0.19041.1                          
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          10.0.19041.423                        
    hyperkbd         hyperkbd                                                                hyperkbd.sys          10.0.19041.1                          
    HyperVideo       HyperVideo                                                              HyperVideo.sys        10.0.19041.1                          
    i8042prt          i8042-     PS/2                          i8042prt.sys          10.0.19041.1                          
    iagpio             GPIO   - Intel        iagpio.sys            1.1.1.0                               
    iai2c            Intel(R) Serial IO I2C Host Controller                                  iai2c.sys             1.1.1.0                               
    iaLPSS2i_GPIO2_BXT_P   2  -      - Intel(R)  iaLPSS2i_GPIO2_BXT_P.sys  30.100.1816.1                         
    iaLPSS2i_GPIO2_CNL    2  -      - Intel(R)  iaLPSS2i_GPIO2_CNL.sys  30.100.1816.3                         
    iaLPSS2i_GPIO2_GLK    2  -      - Intel(R)  iaLPSS2i_GPIO2_GLK.sys  30.100.1820.1                         
    iaLPSS2i_GPIO2    2 Intel(R) Serial IO GPIO                                iaLPSS2i_GPIO2.sys    30.100.1816.3                         
    iaLPSS2i_I2C_BXT_P   2 I2C    - Intel(R)  iaLPSS2i_I2C_BXT_P.sys  30.100.1816.1                         
    iaLPSS2i_I2C_CNL    2  -      - Intel(R)  iaLPSS2i_I2C_CNL.sys  30.100.1929.1                         
    iaLPSS2i_I2C_GLK    2  -      - Intel(R)  iaLPSS2i_I2C_GLK.sys  30.100.1820.1                         
    iaLPSS2i_I2C      2 Intel(R) Serial IO I2C                                 iaLPSS2i_I2C.sys      30.100.1816.3                         
    iaLPSSi_GPIO       Intel(R) Serial IO GPIO                             iaLPSSi_GPIO.sys      1.1.250.0                             
    iaLPSSi_I2C       Intel(R) Serial IO I2C Controller                               iaLPSSi_I2C.sys       1.1.253.0                             
    iaStorAVC        RAID- SATA    Intel                         iaStorAVC.sys         15.44.0.1015                          
    iaStorV          RAID- Intel  Windows 7                                     iaStorV.sys           8.6.2.1019                            
    ibbus            Mellanox InfiniBand Bus/AL ( )                            ibbus.sys             5.50.14695.0                          
    IndirectKmd                                             IndirectKmd.sys       10.0.19041.546                        
    IntcAzAudAddService  Service for Realtek HD Audio (WDM)                                      RTKVHD64.sys          6.0.8703.1                            
    intelide         intelide                                                                intelide.sys          10.0.19041.1889                       
    intelpep              Intel(R)               intelpep.sys          10.0.19041.1266                       
    intelpmax          Intel(R) Dynamic Device Peak Power Manager           intelpmax.sys         10.0.19041.1                          
    intelppm          Intel                                                 intelppm.sys          10.0.19041.2728                       
    iorate              -                              iorate.sys            10.0.19041.1052                       
    IpFilterDriver     IP-                                              ipfltdrv.sys          10.0.19041.2075                       
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           10.0.19041.1052                       
    IPNAT            IP Network Address Translator                                           ipnat.sys             10.0.19041.2846                       
    IPT              IPT                                                                     ipt.sys               10.0.19041.1                          
    isapnp           isapnp                                                                  isapnp.sys            10.0.19041.1202                       
    iScsiPrt          iScsiPort                                                       msiscsi.sys           10.0.19041.2965                       
    ItSas35i         ItSas35i                                                                ItSas35i.sys          2.60.94.80                            
    kbdclass                                                          kbdclass.sys          10.0.19041.1                          
    kbdhid             HID                                                  kbdhid.sys            10.0.19041.1                          
    kbldfltr         kbldfltr                                                                kbldfltr.sys          10.0.19041.844                        
    kdnic            -      () (NDIS 6.20)    kdnic.sys             6.1.0.0                               
    KSecDD           KSecDD                                                                  ksecdd.sys            10.0.19041.2130                       
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           10.0.19041.2913                       
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           10.0.19041.1                          
    lltdio                                       lltdio.sys            10.0.19041.1                          
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.34.3.83                             
    LSI_SAS2i        LSI_SAS2i                                                               lsi_sas2i.sys         2.0.79.82                             
    LSI_SAS3i        LSI_SAS3i                                                               lsi_sas3i.sys         2.51.26.80                            
    LSI_SSS          LSI_SSS                                                                 lsi_sss.sys           2.10.61.81                            
    luafv                                            luafv.sys             10.0.19041.2546            
    mausbhost         - MA-USB                                         mausbhost.sys         10.0.19041.1                          
    mausbip           IP- MA-USB                                                mausbip.sys           10.0.19041.1                          
    MbbCx            MBB Network Adapter Class Extension                                     MbbCx.sys             10.0.19041.1620                       
    megasas          megasas                                                                 megasas.sys           6.706.6.0                             
    megasas2i        megasas2i                                                               MegaSas2i.sys         6.714.20.0                            
    megasas35i       megasas35i                                                              megasas35i.sys        7.710.10.0                            
    megasr           megasr                                                                  megasr.sys            15.2.2013.129                         
    Microsoft_Bluetooth_AvrcpTransport    AVRCP Microsoft Bluetooth                            Microsoft.Bluetooth.AvrcpTransport.sys  10.0.19041.1                          
    mlx4_bus           Mellanox ConnectX                                    mlx4_bus.sys          5.50.14695.0                          
    MMCSS            Multimedia Class Scheduler                                              mmcss.sys             10.0.19041.546                        
    Modem            Modem                                                                   modem.sys             10.0.19041.746                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           10.0.19041.1151                       
    mouclass                                                                mouclass.sys          10.0.19041.1                          
    mouhid             HID                                                        mouhid.sys            10.0.19041.1                          
    mountmgr                                                        mountmgr.sys          10.0.19041.1                          
    mpsdrv           Windows Defender Firewall Authorization Driver                          mpsdrv.sys            10.0.19041.1                          
    mracdrv          MRAC Driver                                                             mracdrv1.sys          3.89.0.0                              
    MRxDAV              WebDav                                 mrxdav.sys            10.0.19041.1566            
    mrxsmb              - SMB                              mrxsmb.sys            10.0.19041.2075            
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          10.0.19041.2913            
    MsBridge         MAC- ()                                                   bridge.sys            10.0.19041.1                          
    Msfs             Msfs                                                                                                                     
    msgpiowin32         ,     /  msgpiowin32.sys       10.0.19041.1                          
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         10.0.19041.1                          
    mshidumdf          HID-UMDF                                               mshidumdf.sys         10.0.19041.1                          
    msisadrv         msisadrv                                                                msisadrv.sys          10.0.19041.1202                       
    MSKSSRV             Microsoft                                   MSKSSRV.sys           10.0.19041.2913                       
    MsLldp            Microsoft LLDP                                                 mslldp.sys            10.0.19041.1                          
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          10.0.19041.1                          
    MSPQM                Microsoft                     MSPQM.sys             10.0.19041.1                          
    MsQuic           MsQuic                                                                  msquic.sys            10.0.19041.488                        
    MsRPC            MsRPC                                                                                                                               
    MsSecCore           Microsoft Security                                msseccore.sys         10.0.19041.2788                       
    MsSecFlt         -                      mssecflt.sys          10.0.19041.2788                       
    MsSecWfp           Microsoft Security WFP                                   mssecwfp.sys          10.0.19041.2788                       
    mssmbios          Microsoft System Management BIOS                                mssmbios.sys          10.0.19041.1                          
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             10.0.19041.1                          
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          10.0.19041.1                          
    Mup              Mup                                                                     mup.sys               10.0.19041.2311            
    mvumis           mvumis                                                                  mvumis.sys            1.0.5.1016                            
    NativeWifiP       NativeWiFi                                                       nwifi.sys             10.0.19041.1415                       
    ndfltr            NetworkDirect                                                    ndfltr.sys            5.50.14695.0                          
    NDIS               NDIS                                                  ndis.sys              10.0.19041.1387                       
    NdisCap           Microsoft NDIS                                                   ndiscap.sys           10.0.19041.1                          
    NdisImPlatform       ()                  NdisImPlatform.sys    10.0.19041.546                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          10.0.19041.546                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           10.0.19041.1                          
    NdisVirtualBus       ()                NdisVirtualBus.sys    10.0.19041.1                          
    NdisWan          NDIS-                          ndiswan.sys           10.0.19041.2846                       
    ndiswanlegacy      NDIS-       ndiswan.sys           10.0.19041.2846                       
    NDKPing          NDKPing Driver                                                          NDKPing.sys           10.0.19041.1                          
    ndproxy          NDIS Proxy Driver                                                       NDProxy.sys           10.0.19041.546                        
    Ndu              Windows Network Data Usage Monitoring Driver                            Ndu.sys               10.0.19041.1                          
    NetAdapterCx     Network Adapter Wdf Class Extension Library                             NetAdapterCx.sys      10.0.19041.1620                       
    NetBIOS          NetBIOS Interface                                                       netbios.sys           10.0.19041.1               
    NetBT            NetBT                                                                   netbt.sys             10.0.19041.572                        
    netvsc           netvsc                                                                  netvsc.sys            10.0.19041.1741                       
    Npfs             Npfs                                                                                                                     
    npsvctrig        Named pipe service trigger provider                                     npsvctrig.sys         10.0.19041.1                          
    nsiproxy         NSI Proxy Service Driver                                                nsiproxy.sys          10.0.19041.546                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nvdimm             () NVDIMM                                  nvdimm.sys            10.0.19041.1                          
    NVHDA            Service for NVIDIA High Definition Audio Driver                         nvhda64v.sys          1.3.40.14                             
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          31.0.15.3667                          
    NvModuleTracker  NvModuleTracker                                                         NvModuleTracker.sys   103.0.0.0                             
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.23                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.23                             
    nvvad_WaveExtensible  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)                     nvvad64v.sys          4.49.0.0                              
    nvvhci           NVVHCI Enumerator Service                                               nvvhci.sys            305.0.0.0                             
    Parport                                                         parport.sys           10.0.19041.1                          
    partmgr                                                                   partmgr.sys           10.0.19041.2728                       
    pci                PCI                                                        pci.sys               10.0.19041.1949                       
    pciide           pciide                                                                  pciide.sys            10.0.19041.1889                       
    pcmcia           pcmcia                                                                  pcmcia.sys            10.0.19041.1                          
    pcw              Performance Counters for Windows Driver                                 pcw.sys               10.0.19041.1826                       
    pdc              pdc                                                                     pdc.sys               10.0.19041.1052                       
    PEAUTH           PEAUTH                                                                  peauth.sys            10.0.19041.2965                       
    percsas2i        percsas2i                                                               percsas2i.sys         6.805.3.0                             
    percsas3i        percsas3i                                                               percsas3i.sys         6.604.6.0                             
    PktMon           Packet Monitor Driver                                                   PktMon.sys            10.0.19041.2913                       
    pmem                 ()                     pmem.sys              10.0.19041.1949                       
    PNPMEM              (Microsoft)                                       pnpmem.sys            10.0.19041.1                          
    portcfg          portcfg                                                                 portcfg.sys           10.0.19041.1                          
    PptpMiniport     -   (PPTP)                                        raspptp.sys           10.0.19041.2728                       
    Processor                                                               processr.sys          10.0.19041.2728                       
    Psched             QoS                                                 pacer.sys             10.0.19041.546                        
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          10.0.19041.1                          
    Ramdisk          Windows RAM Disk Driver                                                 ramdisk.sys           10.0.19041.1                          
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            10.0.19041.546                        
    RasAgileVpn      -   (IKEv2)                                       AgileVpn.sys          10.0.19041.2846                       
    Rasl2tp          -   (L2TP)                                        rasl2tp.sys           10.0.19041.2913                       
    RasPppoe          PPPOE                                       raspppoe.sys          10.0.19041.2846                       
    RasSstp          -   (SSTP)                                        rassstp.sys           10.0.19041.2846                       
    rdbss                                               rdbss.sys             10.0.19041.1806            
    rdpbus                          rdpbus.sys            10.0.19041.1                          
    RDPDR                               rdpdr.sys             10.0.19041.906                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  10.0.19041.2913                       
    rdyboost         ReadyBoost                                                              rdyboost.sys          10.0.19041.1                          
    ReFS             ReFS                                                                                                                     
    ReFSv1           ReFSv1                                                                                                                   
    RFCOMM           Bluetooth Device (RFCOMM Protocol TDI)                                  rfcomm.sys            10.0.19041.1                          
    rhproxy           -                                    rhproxy.sys           10.0.19041.1                          
    rspndr                           rspndr.sys            10.0.19041.1                          
    rt640x64         Realtek RT640 NT Driver                                                 rt640x64.sys          10.36.701.2019                        
    s3cap            s3cap                                                                   vms3cap.sys           10.0.19041.1                          
    sbp2port         SBP-2   /                                   sbp2port.sys          10.0.19041.1288                       
    scfilter           -  PnP                                  scfilter.sys          10.0.19041.2486                       
    scmbus            Microsoft                              scmbus.sys            10.0.19041.1503                       
    sdbus            sdbus                                                                   sdbus.sys             10.0.19041.2075                       
    SDFRd             SDF                                                          SDFRd.sys             10.0.19041.1                          
    sdstor             SD Storage                                                sdstor.sys            10.0.19041.1288                       
    SerCx            Serial UART Support Library                                             SerCx.sys             10.0.19041.1                          
    SerCx2           Serial UART Support Library                                             SerCx2.sys            10.0.19041.1                          
    Serenum            Serenum                                                 serenum.sys           10.0.19041.1                          
    Serial                                                      serial.sys            10.0.19041.1                          
    sermouse            .                                             sermouse.sys          10.0.19041.1                          
    sfloppy                                                            sfloppy.sys           10.0.19041.1                          
    SgrmAgent        System Guard Runtime Monitor Agent                                      SgrmAgent.sys         10.0.19041.1                          
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    SmartSAMD        SmartSAMD                                                               SmartSAMD.sys         1.50.1.0                              
    smbdirect        smbdirect                                                               smbdirect.sys         10.0.19041.1               
    spaceparser      Space Parser                                                            spaceparser.sys       10.0.19041.1                          
    spaceport                                                    spaceport.sys         10.0.19041.2846                       
    SpatialGraphFilter  Holographic Spatial Graph Filter                                        SpatialGraphFilter.sys  10.0.19041.1                          
    SpbCx            Simple Peripheral Bus Support Library                                   SpbCx.sys             10.0.19041.1                          
    srv2               Server SMB 2.xxx                                        srv2.sys              10.0.19041.2913            
    srvnet           srvnet                                                                  srvnet.sys            10.0.19041.2913            
    stexstor         stexstor                                                                stexstor.sys          5.1.0.10                              
    storahci           SATA AHCI ()                              storahci.sys          10.0.19041.1889                       
    storflt            Microsoft Hyper-V                                  vmstorfl.sys          10.0.19041.964                        
    stornvme           NVM Express ()                            stornvme.sys          10.0.19041.2075                       
    storqosflt       -                             storqosflt.sys        10.0.19041.1               
    storufs             - (UFS) Microsoft              storufs.sys           10.0.19041.2913                       
    storvsc          storvsc                                                                 storvsc.sys           10.0.19041.1                          
    swenum                                                             swenum.sys            10.0.19041.1                          
    Synth3dVsc       Synth3dVsc                                                              Synth3dVsc.sys        10.0.19041.928                        
    Tcpip              TCP/IP                                                tcpip.sys             10.0.19041.2913                       
    Tcpip6           @todo.dll,-100;Microsoft IPv6 Protocol Driver                           tcpip.sys             10.0.19041.2913                       
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          10.0.19041.2913                       
    tdx                NetIO Legacy TDI                                      tdx.sys               10.0.19041.1237                       
    Telemetry          Intel(R)                                              IntelTA.sys           10.0.19041.546                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          10.0.19041.1                          
    TPM              TPM                                                                     tpm.sys               10.0.19041.2788                       
    TsUsbFlt         -  USB-          tsusbflt.sys          10.0.19041.1                          
    TsUsbGD           USB-                     TsUsbGD.sys           10.0.19041.1151                       
    tsusbhub         Remote Desktop USB Hub                                                  tsusbhub.sys          10.0.19041.1586                       
    tunnel                ()                     tunnel.sys            10.0.19041.2193                       
    UASPStor          USB- SCSI (UAS)                                       uaspstor.sys          10.0.19041.1949                       
    UcmCx0101        USB Connector Manager KMDF Class Extension                              UcmCx.sys             10.0.19041.1266                       
    UcmTcpciCx0101   UCM-TCPCI KMDF Class Extension                                          UcmTcpciCx.sys        10.0.19041.1                          
    UcmUcsiAcpiClient   ACPI UCM-UCSI                                                    UcmUcsiAcpiClient.sys  10.0.19041.1                          
    UcmUcsiCx0101    UCM-UCSI KMDF Class Extension                                           UcmUcsiCx.sys         10.0.19041.488                        
    Ucx01000         USB Host Support Library                                                ucx01000.sys          10.0.19041.1                          
    UdeCx            USB Device Emulation Support Library                                    udecx.sys             10.0.19041.1                          
    udfs             udfs                                                                    udfs.sys              10.0.19041.1               
    UEFI              UEFI ()                                               UEFI.sys              10.0.19041.1                          
    UevAgentDriver   UevAgentDriver                                                          UevAgentDriver.sys    10.0.19041.1320            
    Ufx01000         USB Function Class Extension                                            ufx01000.sys          10.0.19041.1320                       
    UfxChipidea      USB- Chipidea                                                 UfxChipidea.sys       10.0.19041.1                          
    ufxsynopsys      USB- Synopsys                                                  ufxsynopsys.sys       10.0.19041.2193                       
    umbus            UMBus                                               umbus.sys             10.0.19041.1                          
    UmPass            UMPass Microsoft                                                umpass.sys            10.0.19041.1                          
    UrsChipidea          Chipidea USB                              urschipidea.sys       10.0.19041.1                          
    UrsCx01000       USB Role-Switch Support Library                                         urscx01000.sys        10.0.19041.1                          
    UrsSynopsys          Synopsys USB                              urssynopsys.sys       10.0.19041.1                          
    usbaudio           USB (WDM)                                                 usbaudio.sys          10.0.19041.2604                       
    usbaudio2         USB Audio 2.0                                                    usbaudio2.sys         10.0.19041.1                          
    usbccgp              USB (Microsoft)         usbccgp.sys           10.0.19041.2546                       
    usbcir           eHome   (USBCIR)                                     usbcir.sys            10.0.19041.1                          
    usbehci            Microsoft USB 2.0  -       usbehci.sys           10.0.19041.1                          
    usbhub             USB- ()                      usbhub.sys            10.0.19041.1                          
    USBHUB3           SuperSpeed                                                 UsbHub3.sys           10.0.19041.1202                       
    usbohci            Microsoft USB  -              usbohci.sys           10.0.19041.1                          
    usbprint           Microsoft USB                                           usbprint.sys          10.0.19041.2788                       
    usbser              USB ()                        usbser.sys            10.0.19041.2130                       
    USBSTOR              USB                                  USBSTOR.SYS           10.0.19041.1949                       
    usbuhci            Microsoft USB  -         usbuhci.sys           10.0.19041.1                          
    USBXHCI          xHCI- - USB                                    USBXHCI.SYS           10.0.19041.2546                       
    vdrvroot            ()                           vdrvroot.sys          10.0.19041.1                          
    VerifierExt                                           VerifierExt.sys       10.0.19041.1                          
    vhdmp            vhdmp                                                                   vhdmp.sys             10.0.19041.2311                       
    vhf                Virtual HID Framework (VHF)                           vhf.sys               10.0.19041.1                          
    Vid              Vid                                                                     Vid.sys               10.0.19041.2311                       
    VirtualRender    VirtualRender                                                           vrd.sys               10.0.19041.1                          
    vmbus             VMBus                                                              vmbus.sys             10.0.19041.1949                       
    VMBusHID         VMBusHID                                                                VMBusHID.sys          10.0.19041.1                          
    vmgid               Microsoft Hyper-V                         vmgid.sys             10.0.19041.1                          
    volmgr                                                             volmgr.sys            10.0.19041.1806                       
    volmgrx                                                        volmgrx.sys           10.0.19041.1                          
    volsnap                                                    volsnap.sys           10.0.19041.488                        
    volume                                                                        volume.sys            10.0.19041.1                          
    vpci               PCI Microsoft Hyper-V                                  vpci.sys              10.0.19041.2546                       
    vsmraid          vsmraid                                                                 vsmraid.sys           7.0.9600.6352                         
    VSTXRAID          RAID-   VIA StorX  Windows  vstxraid.sys          8.0.9200.8110                         
    vwifibus         Virtual Wireless Bus Driver                                             vwifibus.sys          10.0.19041.1                          
    vwififlt         Virtual WiFi Filter Driver                                              vwififlt.sys          10.0.19041.1202                       
    WacomPen         Wacom -                                wacompen.sys          10.0.19041.1                          
    wanarp            IP ARP                                      wanarp.sys            10.0.19041.546                        
    wanarpv6          IPv6 ARP                                    wanarp.sys            10.0.19041.546                        
    wcifs            Windows Container Isolation                                             wcifs.sys             10.0.19041.2913            
    wcnfs            Windows Container Name Virtualization                                   wcnfs.sys             10.0.19041.1766            
    WdBoot               Microsoft Defender              WdBoot.sys            4.18.23050.5                          
    Wdf01000                                                 Wdf01000.sys          1.31.19041.2193                       
    WdFilter            -     Microsoft Defender  WdFilter.sys          4.18.23050.5               
    wdiwifi          WDI Driver Framework                                                    wdiwifi.sys           10.0.19041.2788                       
    WdmCompanionFilter  WdmCompanionFilter                                                      WdmCompanionFilter.sys  10.0.19041.1                          
    WdNisDrv                 Microsoft Defender  WdNisDrv.sys          4.18.23050.5                          
    WFPLWFS            Microsoft Windows                                  wfplwfs.sys           10.0.19041.2913                       
    WIMMount         WIMMount                                                                wimmount.sys          10.0.19041.1202            
    WindowsTrustedRT  Windows Trusted Execution Environment Class Extension                   WindowsTrustedRT.sys  10.0.19041.1                          
    WindowsTrustedRTProxy       Microsoft Windows       WindowsTrustedRTProxy.sys  10.0.19041.1                          
    WinMad            WinMad                                                           winmad.sys            5.50.14695.0                          
    WinNat            NAT Windows                                                     winnat.sys            10.0.19041.1566                       
    WinRing0_1_2_0   WinRing0_1_2_0                                                          tmp7E2B.tmp           1.2.0.5                               
    WINUSB            WinUsb                                                          WinUSB.SYS            10.0.19041.1                          
    WinVerbs          WinVerbs                                                         winverbs.sys          5.50.14695.0                          
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           10.0.19041.1                          
    Wof              Windows Overlay File System Filter Driver                                                                                
    WpdUpFltr        WPD Upper Class Filter Driver                                           WpdUpFltr.sys         10.0.19041.1                          
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           10.0.19041.1                          
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            10.0.19041.1865                       
    WUDFRd           Windows Driver Foundation - User-mode Driver Framework Reflector        WUDFRd.sys            10.0.19041.1865                       
    xboxgip              Xbox                                   xboxgip.sys           10.0.19041.1566                       
    xhunter1         xhunter1                                                                xhunter1.sys          3.4.2.151                             
    xinputhid        - HID XINPUT                                               xinputhid.sys         10.0.19041.2788                       


--------[  ]------------------------------------------------------------------------------------------------------

    AarSvc_6a215                       Agent Activation Runtime_6a215                                          svchost.exe           10.0.19041.1806                        
    Addappter Service                  Addappter Service                                                       Configurator.Service.WindowsService.DNS.exe  2022.3.51568.0                 LocalSystem
    AJRouter                             AllJoyn                                           svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    ALG                                                                             alg.exe               10.0.19041.746                 NT AUTHORITY\LocalService
    AppIDSvc                                                                            svchost.exe           10.0.19041.1806                      NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           10.0.19041.1806                        LocalSystem
    AppMgmt                                                                              svchost.exe           10.0.19041.1806                        LocalSystem
    AppReadiness                                                                           svchost.exe           10.0.19041.1806                      LocalSystem
    AppVClient                         Microsoft App-V Client                                                  AppVClient.exe        10.0.19041.2673                LocalSystem
    AppXSvc                              AppX (AppXSVC)                                     svchost.exe           10.0.19041.1806                        LocalSystem
    AssignedAccessManagerSvc            AssignedAccessManager                                            svchost.exe           10.0.19041.1806                      LocalSystem
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           10.0.19041.1806                        LocalSystem
    Audiosrv                           Windows Audio                                                           svchost.exe           10.0.19041.1806                NT AUTHORITY\LocalService
    autotimesvc                                                                        svchost.exe           10.0.19041.1806                NT AUTHORITY\LocalService
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           10.0.19041.1806                      LocalSystem
    BcastDVRUserService_6a215            DVR    _6a215                  svchost.exe           10.0.19041.1806                        
    BDESVC                                BitLocker                                      svchost.exe           10.0.19041.1806                      localSystem
    BEService                          BattlEye Service                                                        BEService.exe                                        LocalSystem
    BFE                                                                                 svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           10.0.19041.1806                      LocalSystem
    BluetoothUserService_6a215            Bluetooth_6a215                          svchost.exe           10.0.19041.1806                        
    BrokerInfrastructure                                                       svchost.exe           10.0.19041.1806                      LocalSystem
    BTAGService                           Bluetooth                                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    BthAvctpSvc                         AVCTP                                                            svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    bthserv                              Bluetooth                                              svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    camsvc                                                                 svchost.exe           10.0.19041.1806                        LocalSystem
    CaptureService_6a215               CaptureService_6a215                                                    svchost.exe           10.0.19041.1806                        
    cbdhsvc_6a215                         _6a215                             svchost.exe           10.0.19041.1806                        
    CDPSvc                                                                 svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    CDPUserSvc_6a215                       _6a215              svchost.exe           10.0.19041.1806                        
    CertPropSvc                                                                      svchost.exe           10.0.19041.1806                      LocalSystem
    ClipSVC                               (ClipSVC)                                       svchost.exe           10.0.19041.1806                        LocalSystem
    cloudidsvc                             ()                svchost.exe           10.0.19041.1806                NT AUTHORITY\NetworkService
    COMSysApp                            COM+                                               dllhost.exe           10.0.19041.546                 LocalSystem
    ConsentUxUserSvc_6a215             ConsentUX_6a215                                                         svchost.exe           10.0.19041.1806                        
    CoreMessagingRegistrar             CoreMessaging                                                           svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    CredentialEnrollmentManagerUserSvc_6a215  CredentialEnrollmentManagerUserSvc_6a215                                CredentialEnrollmentManager.exe  10.0.19041.1202                        
    CryptSvc                                                                                 svchost.exe           10.0.19041.1806                        NT Authority\NetworkService
    CscService                                                                                  svchost.exe           10.0.19041.1806                      LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           10.0.19041.1806                      LocalSystem
    dcsvc                              dcsvc                                                                   svchost.exe           10.0.19041.1806                LocalSystem
    defragsvc                                                                                 svchost.exe           10.0.19041.1806                localSystem
    DeviceAssociationBrokerSvc_6a215   DeviceAssociationBroker_6a215                                           svchost.exe           10.0.19041.1806                        
    DeviceAssociationService                                                       svchost.exe           10.0.19041.1806                      LocalSystem
    DeviceInstall                                                                      svchost.exe           10.0.19041.1806                      LocalSystem
    DevicePickerUserSvc_6a215          DevicePicker_6a215                                                      svchost.exe           10.0.19041.1806                        
    DevicesFlowUserSvc_6a215           DevicesFlow_6a215                                                       svchost.exe           10.0.19041.1806                        
    DevQueryBroker                        DevQuery                                    svchost.exe           10.0.19041.1806                      LocalSystem
    Dhcp                               DHCP-                                                             svchost.exe           10.0.19041.1806                        NT Authority\LocalService
    diagnosticshub.standardcollector.service       Microsoft (R)            DiagnosticsHub.StandardCollector.Service.exe  11.0.19041.1466                LocalSystem
    diagsvc                            Diagnostic Execution Service                                            svchost.exe           10.0.19041.1806                      LocalSystem
    DiagTrack                                  svchost.exe           10.0.19041.1806                LocalSystem
    DialogBlockingService              DialogBlockingService                                                   svchost.exe           10.0.19041.1806                      LocalSystem
    DispBrokerDesktopSvc                                                              svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    DisplayEnhancementService                                                        svchost.exe           10.0.19041.1806                        LocalSystem
    DmEnrollmentSvc                                                      svchost.exe           10.0.19041.1806                LocalSystem
    dmwappushservice                     push-    WAP (Wireless Application Protocol)     svchost.exe           10.0.19041.1806                      LocalSystem
    Dnscache                           DNS-                                                              svchost.exe           10.0.19041.1806                        NT AUTHORITY\NetworkService
    DoSvc                                                                                   svchost.exe           10.0.19041.1806                        NT Authority\NetworkService
    dot3svc                                                                              svchost.exe           10.0.19041.1806                      localSystem
    DPS                                                                               svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    DsmSvc                                                                          svchost.exe           10.0.19041.1806                      LocalSystem
    DsSvc                                                                       svchost.exe           10.0.19041.1806                      LocalSystem
    DusmSvc                                                                                 svchost.exe           10.0.19041.1806                NT Authority\LocalService
    Eaphost                                (EAP)                         svchost.exe           10.0.19041.1806                      localSystem
    edgeupdate                         Microsoft Edge Update Service (edgeupdate)                              MicrosoftEdgeUpdate.exe  1.3.147.37                     LocalSystem
    edgeupdatem                        Microsoft Edge Update Service (edgeupdatem)                             MicrosoftEdgeUpdate.exe  1.3.147.37                     LocalSystem
    EFS                                   (EFS)                                      lsass.exe             10.0.19041.2130                      LocalSystem
    embeddedmode                                                                                svchost.exe           10.0.19041.1806                      LocalSystem
    EntAppSvc                                                        svchost.exe           10.0.19041.1806                      LocalSystem
    EventLog                             Windows                                                  svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    FACEITService                      FACEITService                                                           faceitservice.exe     2.0.0.0                        LocalSystem
    Fax                                                                                                    fxssvc.exe            10.0.19041.2604                NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    fhsvc                                                                                   svchost.exe           10.0.19041.1806                      LocalSystem
    FontCache                             Windows                                             svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.9141                  NT Authority\LocalService
    FrameServer                           Windows                                            svchost.exe           10.0.19041.1806                      LocalSystem
    FvSvc                              NVIDIA FrameView SDK service                                            nvfvsdksvc_x64.exe    1.3.8513.0                     LocalSystem
    GoogleChromeElevationService       Google Chrome Elevation Service (GoogleChromeElevationService)          elevation_service.exe  114.0.5735.199                 LocalSystem
    gpsvc                                                                               svchost.exe           10.0.19041.1806                        LocalSystem
    GraphicsPerfSvc                    GraphicsPerfSvc                                                         svchost.exe           10.0.19041.1806                        LocalSystem
    gupdate                             Google Update (gupdate)                                          GoogleUpdate.exe      1.3.36.151                     LocalSystem
    gupdatem                            Google Update (gupdatem)                                         GoogleUpdate.exe      1.3.36.151                     LocalSystem
    hidserv                               HID                                                svchost.exe           10.0.19041.1806                        LocalSystem
    HvHost                               HV                                                          svchost.exe           10.0.19041.1806                      LocalSystem
    icssvc                              Windows Mobile Hotspot                                           svchost.exe           10.0.19041.1806                      NT Authority\LocalService
    IKEEXT                               IPsec        IP     svchost.exe           10.0.19041.1806                      LocalSystem
    InstallService                       Microsoft Store                                        svchost.exe           10.0.19041.1806                LocalSystem
    iphlpsvc                             IP                                               svchost.exe           10.0.19041.1806                        LocalSystem
    IpxlatCfgSvc                          IP-                              svchost.exe           10.0.19041.1806                      LocalSystem
    KeyIso                               CNG                                                     lsass.exe             10.0.19041.2130                      LocalSystem
    KtmRm                              KtmRm                            svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           10.0.19041.1806                        LocalSystem
    LanmanWorkstation                                                                            svchost.exe           10.0.19041.1806                        NT AUTHORITY\NetworkService
    lfsvc                                                                        svchost.exe           10.0.19041.1806                        LocalSystem
    LicenseManager                      Windows License Manager                                          svchost.exe           10.0.19041.1806                        NT Authority\LocalService
    lltdsvc                                                                             svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    LSM                                                                               svchost.exe           10.0.19041.1806                        LocalSystem
    LxpSvc                              Language Experience Service                                      svchost.exe           10.0.19041.1806                        LocalSystem
    MapsBroker                                                                           svchost.exe           10.0.19041.1806                NT AUTHORITY\NetworkService
    McpManagementService               McpManagementService                                                    svchost.exe           10.0.19041.1806                LocalSystem
    MessagingService_6a215             MessagingService_6a215                                                  svchost.exe           10.0.19041.1806                        
    MicrosoftEdgeElevationService      Microsoft Edge Elevation Service (MicrosoftEdgeElevationService)        elevation_service.exe  114.0.1823.86                  LocalSystem
    MixedRealityOpenXRSvc              Windows Mixed Reality OpenXR Service                                    svchost.exe           10.0.19041.1806                      LocalSystem
    mpssvc                               Windows                                            svchost.exe           10.0.19041.1806                      NT Authority\LocalService
    mracsvc                            MRAC Service                                                            mracsvc.exe           4.0.1.0                        LocalSystem
    MSDTC                                                                   msdtc.exe             2001.12.10941.16384                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           10.0.19041.1806                      LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.19041.2193                 LocalSystem
    MsKeyboardFilter                     Microsoft                                         svchost.exe           10.0.19041.1806                      LocalSystem
    NaturalAuthentication                                       svchost.exe           10.0.19041.1806                      LocalSystem
    NcaSvc                                                                           svchost.exe           10.0.19041.1806                      LocalSystem
    NcbService                                                                        svchost.exe           10.0.19041.1806                        LocalSystem
    NcdAutoSetup                                                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    Netlogon                                                                                lsass.exe             10.0.19041.2130                      LocalSystem
    Netman                                                                                   svchost.exe           10.0.19041.1806                      LocalSystem
    netprofm                                                                                  svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    NetSetupSvc                                                                             svchost.exe           10.0.19041.1806                        LocalSystem
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.8.4084.0                           NT AUTHORITY\LocalService
    NgcCtnrSvc                           Microsoft Passport                                     svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    NgcSvc                              Microsoft Passport                                               svchost.exe           10.0.19041.1806                      LocalSystem
    NlaSvc                                                                     svchost.exe           10.0.19041.1806                        NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           10.0.19041.1806                        NT Authority\LocalService
    NvContainerLocalSystem             NVIDIA LocalSystem Container                                            nvcontainer.exe       1.37.3103.4323                 LocalSystem
    NVDisplay.ContainerLocalSystem     NVIDIA Display Container LS                                             NVDisplay.Container.exe  1.37.3103.4323                 LocalSystem
    OneSyncSvc_6a215                    _6a215                                                svchost.exe           10.0.19041.1806                        
    ose64                              Office 64 Source Engine                                                 OSE.EXE               16.0.4266.1001                 LocalSystem
    p2pimsvc                                                            svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           10.0.19041.1806                        LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    perceptionsimulation                  Windows                                      PerceptionSimulationService.exe  10.0.19041.746                 LocalSystem
    PerfHost                                                           perfhost.exe          10.0.19041.1                   NT AUTHORITY\LocalService
    PhoneSvc                                                                                    svchost.exe           10.0.19041.1806                        NT Authority\LocalService
    PimIndexMaintenanceSvc_6a215         _6a215                                          svchost.exe           10.0.19041.1806                        
    pla                                                                    svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    PlugPlay                           Plug and Play                                                           svchost.exe           10.0.19041.1806                      LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           10.0.19041.1806                      NT Authority\NetworkService
    Power                                                                                               svchost.exe           10.0.19041.1806                      LocalSystem
    PrintNotify                                                              svchost.exe           10.0.19041.1806                      LocalSystem
    PrintWorkflowUserSvc_6a215         PrintWorkflow_6a215                                                     svchost.exe           10.0.19041.1806                        
    ProfSvc                                                                         svchost.exe           10.0.19041.1806                        LocalSystem
    PushToInstall                       PushToInstall Windows                                            svchost.exe           10.0.19041.1806                        LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           10.0.19041.1806                      localSystem
    RasMan                                                                svchost.exe           10.0.19041.1806                      localSystem
    RemoteAccess                                                                  svchost.exe           10.0.19041.1806                      localSystem
    RemoteRegistry                                                                              svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    RetailDemo                                                                       svchost.exe           10.0.19041.1806                      LocalSystem
    RmSvc                                                                                 svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           10.0.19041.1                   NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    RtkAudioUniversalService           Realtek Audio Universal Service                                         RtkAudUService64.exe  1.0.191.1                      LocalSystem
    SamSs                                                                   lsass.exe             10.0.19041.2130                      LocalSystem
    SCardSvr                           -                                                             svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    ScDeviceEnum                           -                         svchost.exe           10.0.19041.1806                      LocalSystem
    Schedule                                                                                   svchost.exe           10.0.19041.1806                        LocalSystem
    SCPolicySvc                          -                                            svchost.exe           10.0.19041.1806                      LocalSystem
    SDRSVC                                                                             svchost.exe           10.0.19041.1806                localSystem
    seclogon                                                                              svchost.exe           10.0.19041.1806                      LocalSystem
    SecurityHealthService               " Windows"                                           SecurityHealthService.exe  4.18.1907.16384                LocalSystem
    SEMgrSvc                              NFC/                            svchost.exe           10.0.19041.1806                NT AUTHORITY\LocalService
    SENS                                                                    svchost.exe           10.0.19041.1806                        LocalSystem
    Sense                               Advanced Threat Protection   Windows                   MsSense.exe                                          LocalSystem
    SensorDataService                                                                      SensorDataService.exe  10.0.19041.746                 LocalSystem
    SensorService                                                                                svchost.exe           10.0.19041.1806                      LocalSystem
    SensrSvc                                                                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           10.0.19041.1806                      localSystem
    SgrmBroker                             System Guard                        SgrmBroker.exe        10.0.19041.546                 LocalSystem
    SharedAccess                             (ICS)                            svchost.exe           10.0.19041.1806                      LocalSystem
    SharedRealitySvc                                                               svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    ShellHWDetection                                                            svchost.exe           10.0.19041.1806                        LocalSystem
    shpamsvc                           Shared PC Account Manager                                               svchost.exe           10.0.19041.1806                      LocalSystem
    smphost                            SMP   ()                                   svchost.exe           10.0.19041.1806                NT AUTHORITY\NetworkService
    SmsRouter                            SMS Microsoft Windows.                            svchost.exe           10.0.19041.1806                      NT Authority\LocalService
    SNMPTRAP                            SNMP                                                            snmptrap.exe          10.0.19041.1                   NT AUTHORITY\LocalService
    spectrum                             Windows                                               spectrum.exe          10.0.19041.1741                NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           10.0.19041.2788                LocalSystem
    sppsvc                                                                        sppsvc.exe            10.0.19041.2965                NT AUTHORITY\NetworkService
    SSDPSRV                             SSDP                                                        svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    ssh-agent                          OpenSSH Authentication Agent                                            ssh-agent.exe         8.1.0.1                        LocalSystem
    SstpSvc                             SSTP                                                             svchost.exe           10.0.19041.1806                        NT Authority\LocalService
    StateRepository                                                                  svchost.exe           10.0.19041.1806                        LocalSystem
    Steam Client Service               Steam Client Service                                                    steamservice.exe      8.18.16.37                     LocalSystem
    stisvc                                Windows (WIA)                               svchost.exe           10.0.19041.1806                NT Authority\LocalService
    StorSvc                                                                                     svchost.exe           10.0.19041.1806                        LocalSystem
    svsvc                                                                                       svchost.exe           10.0.19041.1806                      LocalSystem
    swprv                                  (Microsoft)                  svchost.exe           10.0.19041.1806                LocalSystem
    SysMain                            SysMain                                                                 svchost.exe           10.0.19041.1806                        LocalSystem
    SystemEventsBroker                                                                   svchost.exe           10.0.19041.1806                      LocalSystem
    TabletInputService                                         svchost.exe           10.0.19041.1806                        LocalSystem
    TapiSrv                                                                                           svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    TermService                                                                    svchost.exe           10.0.19041.1806                      NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           10.0.19041.1806                        LocalSystem
    TieringEngineService                                                            TieringEngineService.exe  10.0.19041.746                 localSystem
    TimeBrokerSvc                                                                                 svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    TokenBroker                          -                                           svchost.exe           10.0.19041.1806                        LocalSystem
    TrkWks                                                                 svchost.exe           10.0.19041.1806                        LocalSystem
    TroubleshootingSvc                                                 svchost.exe           10.0.19041.1806                      LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  10.0.19041.1741                localSystem
    tzautoupdate                                                          svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    ucldr_battlegrounds_gl             Uncheater for BattleGrounds_GL                                          ucldr_battlegrounds_gl.exe  2022.10.27.4                   LocalSystem
    UdkUserSvc_6a215                     UDK_6a215                                       svchost.exe           10.0.19041.1806                        
    UevAgentService                                             AgentService.exe      10.0.19041.2913                LocalSystem
    UmRdpService                                svchost.exe           10.0.19041.1806                      localSystem
    UnistoreSvc_6a215                     _6a215                               svchost.exe           10.0.19041.1806                        
    upnphost                             PNP-                                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    UserDataSvc_6a215                      _6a215                              svchost.exe           10.0.19041.1806                        
    UserManager                                                                          svchost.exe           10.0.19041.1806                        LocalSystem
    UsoSvc                                                                         svchost.exe           10.0.19041.1806                        LocalSystem
    VacSvc                                                                     svchost.exe           10.0.19041.1806                NT AUTHORITY\LocalService
    VaultSvc                                                                             lsass.exe             10.0.19041.2130                      LocalSystem
    vds                                                                                         vds.exe               10.0.19041.1682                LocalSystem
    vmicguestinterface                    Hyper-V                                       svchost.exe           10.0.19041.1806                      LocalSystem
    vmicheartbeat                        (Hyper-V)                                                 svchost.exe           10.0.19041.1806                      LocalSystem
    vmickvpexchange                       (Hyper-V)                                         svchost.exe           10.0.19041.1806                      LocalSystem
    vmicrdv                                 Hyper-V                   svchost.exe           10.0.19041.1806                      LocalSystem
    vmicshutdown                             (Hyper-V)                     svchost.exe           10.0.19041.1806                      LocalSystem
    vmictimesync                          Hyper-V                                    svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    vmicvmsession                       Hyper-V PowerShell Direct                                        svchost.exe           10.0.19041.1806                      LocalSystem
    vmicvss                                  Hyper-V                    svchost.exe           10.0.19041.1806                      LocalSystem
    VSS                                                                                  vssvc.exe             10.0.19041.1741                LocalSystem
    W32Time                              Windows                                                  svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    WaaSMedicSvc                        Medic   Windows                                  svchost.exe           10.0.19041.1806                        LocalSystem
    WalletService                                                                                svchost.exe           10.0.19041.1806                      LocalSystem
    WarpJITSvc                         WarpJITSvc                                                              svchost.exe           10.0.19041.1806                NT Authority\LocalService
    wbengine                                                                wbengine.exe          10.0.19041.746                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           10.0.19041.1806                      LocalSystem
    Wcmsvc                               Windows                                           svchost.exe           10.0.19041.1806                NT Authority\LocalService
    wcncsvc                              Windows -                   svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           10.0.19041.1806                        LocalSystem
    WdNisSvc                                Microsoft Defender          NisSrv.exe            4.18.23050.5                   NT AUTHORITY\LocalService
    WebClient                          -                                                              svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    WEPHOSTSVC                             Windows                               svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    wercplsupport                         "  "                        svchost.exe           10.0.19041.1806                      localSystem
    WerSvc                                Windows                                       svchost.exe           10.0.19041.1806                localSystem
    WFDSConMgrSvc                          Wi-Fi Direct                        svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    WiaRpc                                                               svchost.exe           10.0.19041.1806                      LocalSystem
    WinDefend                             Microsoft Defender                        MsMpEng.exe           4.18.23050.5                   LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           10.0.19041.1806                        localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           10.0.19041.1806                      NT AUTHORITY\NetworkService
    wisvc                                 Windows                                   svchost.exe           10.0.19041.1806                      LocalSystem
    WlanSvc                              WLAN                                               svchost.exe           10.0.19041.1806                LocalSystem
    wlidsvc                                                             svchost.exe           10.0.19041.1806                        LocalSystem
    wlpasvc                                                                  svchost.exe           10.0.19041.1806                      NT Authority\LocalService
    WManSvc                              Windows                                               svchost.exe           10.0.19041.1806                      LocalSystem
    wmiApSrv                             WMI                                          WmiApSrv.exe          10.0.19041.1320                localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    workfolderssvc                                                                                 svchost.exe           10.0.19041.1806                      NT AUTHORITY\LocalService
    WpcMonSvc                                                                              svchost.exe           10.0.19041.1806                LocalSystem
    WPDBusEnum                                                           svchost.exe           10.0.19041.1806                        LocalSystem
    WpnService                           push- Windows                                 svchost.exe           10.0.19041.1806                        LocalSystem
    WpnUserService_6a215                 push- Windows_6a215                  svchost.exe           10.0.19041.1806                        
    wscsvc                                                                         svchost.exe           10.0.19041.1806                        NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.19041.2673                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           10.0.19041.1806                        LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           10.0.19041.1806                      localSystem
    XblAuthManager                        Xbox Live                                svchost.exe           10.0.19041.1806                        LocalSystem
    XblGameSave                           Xbox Live                                             svchost.exe           10.0.19041.1806                      LocalSystem
    XboxGipSvc                         Xbox Accessory Management Service                                       svchost.exe           10.0.19041.1806                      LocalSystem
    XboxNetApiSvc                        Xbox Live                                                svchost.exe           10.0.19041.1806                      LocalSystem
    zksvc                              Zakynthos Service                                                       zksvc.exe             1.0.0.6                        LocalSystem


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aadauthhelper.dll          10.0.19041.2075             Microsoft AAD Auth Helper
    aadtb.dll                  10.0.19041.2913             AAD Token Broker Helper Library
    aadwamextension.dll        10.0.19041.2075              DLL  WAM AAD
    aarsvc.dll                 10.0.19041.1865             Agent Activation Runtime Service
    abovelockapphost.dll       10.0.19041.1949             AboveLockAppHost
    accessibilitycpl.dll       10.0.19041.423                 
    accountaccessor.dll        10.0.19041.746              Sync data model to access accounts
    accountsrt.dll             10.0.19041.746              Accounts RT utilities for mail, contacts, calendar
    acgenral.dll               10.0.19041.2846             Windows Compatibility DLL
    aclayers.dll               10.0.19041.2846             Windows Compatibility DLL
    acledit.dll                10.0.19041.1                   ACL
    aclui.dll                  10.0.19041.1                  
    acppage.dll                10.0.19041.746                  ""
    acspecfc.dll               10.0.19041.423              Windows Compatibility DLL
    actioncenter.dll           10.0.19041.746                 
    actioncentercpl.dll        10.0.19041.423                "   "
    activationclient.dll       10.0.19041.746              Activation Client
    activationmanager.dll      10.0.19041.2006             Activation Manager
    activeds.dll               10.0.19041.746               DLL   AD
    activesyncprovider.dll     10.0.19041.746              The engine that syncs ActiveSync accounts
    actxprxy.dll               10.0.19041.2546             ActiveX Interface Marshaling Library
    acwinrt.dll                10.0.19041.2546             Windows Compatibility DLL
    acwow64.dll                10.0.19041.1023             Windows Compatibility for 32bit Apps on Win64
    acxtrnal.dll               10.0.19041.2846             Windows Compatibility DLL
    adaptivecards.dll          10.0.19041.746              Windows Adaptive Cards API Server
    addressparser.dll          10.0.19041.1                ADDRESSPARSER
    admtmpl.dll                10.0.19041.572               " "
    adprovider.dll             10.0.19041.2006             adprovider DLL
    adrclient.dll              10.0.19041.746                 "  " ()
    adsldp.dll                 10.0.19041.1320             ADs LDAP Provider DLL
    adsldpc.dll                10.0.19041.1023              DLL  LDAP AD
    adsmsext.dll               10.0.19041.1                ADs LDAP Provider DLL
    adsnt.dll                  10.0.19041.1                 DLL    Windows NT
    adtschema.dll              10.0.19041.2788                
    advapi32.dll               10.0.19041.2913               API Windows 32
    advapi32res.dll            10.0.19041.1                  API Windows 32
    advpack.dll                11.0.19041.1                ADVPACK
    aeevts.dll                 10.0.19041.1                    
    aepic.dll                  10.0.19645.1046             Application Experience Program Cache
    agentactivationruntime.dll  10.0.19041.1865             Agent Activation Runtime Common DLL
    agentactivationruntimewindows.dll  10.0.19041.1865             Agent Activation Runtime Windows DLL
    altspace.dll               10.0.19041.1                 
    amsi.dll                   10.0.19041.2075             Anti-Malware Scan Interface
    amstream.dll               10.0.19041.746              DirectShow Runtime.
    analogcommonproxystub.dll  10.0.19041.1                Analog Common Proxy Stub
    apds.dll                   10.0.19041.746                  Microsoft
    aphostclient.dll           10.0.19041.746              Accounts Host Service RPC Client 
    apisethost.appexecutionalias.dll  10.0.19041.1741             ApiSetHost.AppExecutionAlias
    appcontracts.dll           10.0.19041.2193              API Windows AppContracts
    appextension.dll           10.0.19041.746              API AppExtension
    apphelp.dll                10.0.19041.2913                
    apphlpdm.dll               10.0.19041.928                 
    appidapi.dll               10.0.19041.2673             Application Identity APIs Dll
    appidpolicyengineapi.dll   10.0.19041.2673             AppId Policy Engine API Module
    appinstallerprompt.desktop.dll  10.0.19041.746                  AppInstaller
    applockercsp.dll           10.0.19041.2311             AppLockerCSP
    appmanagementconfiguration.dll  10.0.19041.746              Application Management Configuration
    appmgmts.dll               10.0.19041.572                
    appmgr.dll                 10.0.19041.746                 
    appointmentactivation.dll  10.0.19041.1806             DLL for AppointmentActivation
    appointmentapis.dll        10.0.19041.746               DLL  CalendarRT
    apprepapi.dll              10.0.19041.1                Application Reputation APIs Dll
    appresolver.dll            10.0.19041.1620              
    appvclientps.dll           10.0.19041.2546             Microsoft Application Virtualization Client API Proxy Stub
    appventsubsystems32.dll    10.0.19041.2546             Client Virtualization Subsystems
    appvsentinel.dll           10.0.19041.2546             Microsoft Application Virtualization Client Sentinel DLL
    appvterminator.dll         10.0.19041.2546             Microsoft Application Virtualization Terminator
    appxalluserstore.dll       10.0.19041.2788             AppX All User Store DLL
    appxapplicabilityengine.dll  10.0.19041.508              AppX Applicability Engine
    appxdeploymentclient.dll   10.0.19041.2788             DLL-   AppX
    appxpackaging.dll          10.0.19041.2788                 Appx
    appxsip.dll                10.0.19041.2788             Appx Subject Interface Package
    archiveint.dll             3.5.1.0                     Windows-internal libarchive library
    asferror.dll               12.0.19041.1                  ASF
    aspnet_counters.dll        4.8.4084.0                  Microsoft ASP.NET Performance Counter Shim DLL
    assignedaccessruntime.dll  10.0.19041.1320             AssignedAccessRuntime
    asycfilt.dll               10.0.19041.1                ASYCFILT.DLL
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.325              ATL Module for Windows
    atlthunk.dll               10.0.19041.546              atlthunk.dll
    atmlib.dll                 5.1.2.254                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               10.0.19041.1                     
    audioeng.dll               10.0.19041.1503             Audio Engine
    audiokse.dll               10.0.19041.1503             Audio Ks Endpoint
    audioses.dll               10.0.19041.1741               
    auditnativesnapin.dll      10.0.19041.1                      
    auditpolcore.dll           10.0.19041.546                
    auditpolicygpinterop.dll   10.0.19041.746                 
    auditpolmsg.dll            10.0.19041.1                  MMC  
    authbroker.dll             10.0.19041.2130             API WinRT  - 
    authbrokerui.dll           10.0.19041.746                AuthBroker
    authext.dll                10.0.19041.746                 
    authfwcfg.dll              10.0.19041.2913               Windows      
    authfwgp.dll               10.0.19041.2913               Windows c      
    authfwsnapin.dll           10.0.19041.2913             Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           10.0.19041.2913             Wizard Framework
    authui.dll                 10.0.19041.2913               
    authz.dll                  10.0.19041.2913             Authorization Framework
    autoplay.dll               10.0.19041.423               ( )
    avicap32.dll               10.0.19041.1                   AVI
    avifil32.dll               10.0.19041.1                   AVI
    avrt.dll                   10.0.19041.546                   
    azroles.dll                10.0.19041.746              azroles Module
    azroleui.dll               10.0.19041.746               
    azsqlext.dll               10.0.19041.1                AzMan Sql Audit Extended Stored Procedures Dll
    azuresettingsyncprovider.dll  10.0.19041.1806             Azure Setting Sync Provider
    backgroundmediapolicy.dll  10.0.19041.746              <d> Background Media Policy DLL
    bamsettingsclient.dll      10.0.19041.1                Background Activity Moderator Settings Client
    basecsp.dll                10.0.19041.1                   - (Microsoft)
    batmeter.dll               10.0.19041.1                Battery Meter Helper DLL
    bcastdvr.proxy.dll         10.0.19041.1                Broadcast DVR Proxy
    bcastdvrbroker.dll         10.0.19041.746              Windows Runtime BcastDVRBroker DLL
    bcastdvrclient.dll         10.0.19041.746              Windows Runtime BcastDVRClient DLL
    bcastdvrcommon.dll         10.0.19041.746              Windows Runtime BcastDVRCommon DLL
    bcd.dll                    10.0.19041.546              BCD DLL
    bcp47langs.dll             10.0.19041.1566             BCP47 Language Classes
    bcp47mrm.dll               10.0.19041.1503             BCP47 Language Classes for Resource Management
    bcrypt.dll                 10.0.19041.2486                Windows
    bcryptprimitives.dll       10.0.19041.2486             Windows Cryptographic Primitives Library
    bidispl.dll                10.0.19041.1806             Bidispl DLL
    bingmaps.dll               10.0.19041.2788             Bing Map Control
    bingonlineservices.dll     10.0.19041.1                Bing online services
    biocredprov.dll            10.0.19041.1566                WinBio
    bitlockercsp.dll           10.0.19041.2913             BitLockerCSP
    bitsperf.dll               7.8.19041.1                 Perfmon Counter Access
    bitsproxy.dll              7.8.19041.1                 Background Intelligent Transfer Service Proxy
    biwinrt.dll                10.0.19041.1566             Windows Background Broker Infrastructure
    bluetoothapis.dll          10.0.19041.546              Bluetooth Usermode Api host
    bootvid.dll                10.0.19041.1                VGA Boot Driver
    browcli.dll                10.0.19041.1645             Browser Service Client DLL
    browsersettingsync.dll     10.0.19041.746              Browser Setting Synchronization
    browseui.dll               10.0.19041.1                Shell Browser UI Library
    btagservice.dll            10.0.19041.746                 Bluetooth
    bthtelemetry.dll           10.0.19041.1                Bluetooth Telemetry Agent
    btpanui.dll                10.0.19041.746                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    c_g18030.dll               10.0.19041.1                GB18030 DBCS-Unicode Conversion DLL
    c_gsm7.dll                 10.0.19041.1                GSM 7bit Code Page Translation DLL for SMS
    c_is2022.dll               10.0.19041.1                ISO-2022 Code Page Translation DLL
    c_iscii.dll                10.0.19041.1                ISCII Code Page Translation DLL
    cabapi.dll                 10.0.19041.1                Mobile Cabinet Library
    cabinet.dll                5.0.1.1                     Microsoft Cabinet File API
    cabview.dll                10.0.19041.1                   CAB-
    callbuttons.dll            10.0.19041.746              Windows Runtime CallButtonsServer DLL
    callbuttons.proxystub.dll  10.0.19041.1                Windows Runtime CallButtonsServer ProxyStub DLL
    callhistoryclient.dll      10.0.19041.746                DLL     CallHistory
    cameracaptureui.dll        10.0.19041.746              Microsoft Windows Operating System
    capabilityaccessmanagerclient.dll  10.0.19041.746              Capability Access Manager Client
    capauthz.dll               10.0.19041.546              API  
    capiprovider.dll           10.0.19041.2006             capiprovider DLL
    capisp.dll                 10.0.19041.1                Sysprep cleanup dll for CAPI
    castingshellext.dll        10.0.19041.746              Casting Shell Extensions
    catsrv.dll                 2001.12.10941.16384         COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.10941.16384         COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.10941.16384         COM+ Configuration Catalog Server Utilities
    cca.dll                    10.0.19041.1                CCA DirectShow Filter.
    cdosys.dll                 6.6.19041.746               Microsoft CDO for Windows Library
    cdp.dll                    10.0.19041.2913             API  Microsoft (R) CDP
    cdprt.dll                  10.0.19041.2913             API  WinRT  CDP Microsoft (R)
    cemapi.dll                 10.0.19041.746              CEMAPI
    certca.dll                 10.0.19041.1466                Microsoft Active Directory
    certcli.dll                10.0.19041.1466                Microsoft Active Directory
    certcredprovider.dll       10.0.19041.1                   
    certenc.dll                10.0.19041.746              Active Directory Certificate Services Encoding
    certenroll.dll             10.0.19041.2075                 Active Directory Microsoft
    certenrollui.dll           10.0.19041.1                    X509
    certmgr.dll                10.0.19041.2788               
    certpkicmdlet.dll          10.0.19041.804                PKI Microsoft
    certpoleng.dll             10.0.19041.2075               
    cewmdm.dll                 12.0.19041.746                Windows CE WMDM
    cfgbkend.dll               10.0.19041.746              Configuration Backend Interface
    cfgmgr32.dll               10.0.19041.1620             Configuration Manager DLL
    cfmifs.dll                 10.0.19041.746              FmIfs Engine
    cfmifsproxy.dll            10.0.19041.1                Microsoft FmIfs Proxy Library
    chakra.dll                 11.0.19041.2311             Microsoft  Chakra (Private)
    chakradiag.dll             11.0.19041.2251             Microsoft  Chakra Diagnostics (Private)
    chakrathunk.dll            10.0.19041.2251             chakrathunk.dll
    chartv.dll                 10.0.19041.1                Chart View
    chatapis.dll               10.0.19041.746              DLL for ChatRT
    chxreadingstringime.dll    10.0.19041.1                CHxReadingStringIME
    cic.dll                    10.0.19041.1889               CIC - MMC   
    ciwmi.dll                  10.0.19041.662               WMIv2    CI
    clb.dll                    10.0.19041.1                  
    clbcatq.dll                2001.12.10941.16384         COM+ Configuration Catalog
    cldapi.dll                 10.0.19041.1682             Cloud API user mode API
    clfsw32.dll                10.0.19041.21               Common Log Marshalling Win32 DLL
    cliconfg.dll               10.0.19041.1                SQL Client Configuration Utility DLL
    clipboardserver.dll        10.0.19041.746               API Modern Clipboard
    clipc.dll                  10.0.19041.546                 
    cloudexperiencehostcommon.dll  10.0.19041.2788             CloudExperienceHostCommon
    cloudexperiencehostuser.dll  10.0.19041.746              CloudExperienceHost User Operations
    clrhost.dll                10.0.19041.1                In Proc server for managed servers in the Windows Runtime
    clusapi.dll                10.0.19041.1949              API 
    cmcfg32.dll                7.2.19041.1                     Microsoft
    cmdext.dll                 10.0.19041.1                cmd.exe Extension DLL
    cmdial32.dll               7.2.19041.1266               
    cmgrcspps.dll              10.0.19041.1                cmgrcspps
    cmifw.dll                  10.0.19041.964              Windows Defender Firewall rule configuration plug-in
    cmintegrator.dll           10.0.19041.1202             cmintegrator.dll
    cmlua.dll                  7.2.19041.1                   API   
    cmpbk32.dll                7.2.19041.1                 Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.19041.1                   API      
    cmutil.dll                 7.2.19041.1                     (Microsoft)
    cngcredui.dll              10.0.19041.1                 Microsoft CNG CredUI
    cngprovider.dll            10.0.19041.2006             cngprovider DLL
    cnvfat.dll                 10.0.19041.1023             FAT File System Conversion Utility DLL
    colbact.dll                2001.12.10941.16384         COM+
    coloradapterclient.dll     10.0.19041.546              Microsoft Color Adapter Client
    colorcnv.dll               10.0.19041.2604             Windows Media Color Conversion
    colorui.dll                10.0.19041.746                 
    combase.dll                10.0.19041.2788             Microsoft COM  Windows
    comcat.dll                 10.0.19041.1                Microsoft Component Category Manager Library
    comctl32.dll               5.82.19041.1110                  
    comdlg32.dll               10.0.19041.1806                
    coml2.dll                  10.0.19041.546              Microsoft COM for Windows
    compobj.dll                3.10.0.103                  Windows Win16 Application Launcher
    composableshellproxystub.dll  10.0.19041.1                Composable Shell Shared Proxy Stub
    comppkgsup.dll             10.0.19041.746              Component Package Support DLL
    compstui.dll               10.0.19041.1806                  
    comrepl.dll                2001.12.10941.16384         COM+
    comres.dll                 2001.12.10941.16384          COM+
    comsnap.dll                2001.12.10941.16384         COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.10941.16384         COM+ Services
    comuid.dll                 2001.12.10941.16384         COM+ Explorer UI
    concrt140.dll              14.36.32532.0               Microsoft Concurrency Runtime Library
    configureexpandedstorage.dll  10.0.19041.746              ConfigureExpandedStorage
    connect.dll                10.0.19041.746               
    connectedaccountstate.dll  10.0.19041.746              ConnectedAccountState.dll
    console.dll                10.0.19041.746                 
    consolelogon.dll           10.0.19041.2913                 
    contactactivation.dll      10.0.19041.746              DLL for ContactActivation
    contactapis.dll            10.0.19041.746              DLL for ContactsRT
    container.dll              10.0.19041.964              Windows Containers
    contentdeliverymanager.utilities.dll  10.0.19041.2311             ContentDeliveryManager.Utilities
    coreglobconfig.dll         10.0.19041.2913             Core Globalization Configuration
    coremas.dll                                            
    coremessaging.dll          10.0.19041.2193             Microsoft CoreMessaging Dll
    coremmres.dll              10.0.19041.1                General Core Multimedia Resources
    coreshellapi.dll           10.0.19041.746              CoreShellAPI
    coreuicomponents.dll       10.0.19041.546              Microsoft Core UI Components Dll
    cpfilters.dll              10.0.19041.2486              PTFilter & Encypter/Decrypter Tagger Filters.
    credprov2fahelper.dll      10.0.19041.746                  2FA
    credprovdatamodel.dll      10.0.19041.2788             Cred Prov Data Model
    credprovhelper.dll         10.0.19041.928              Credential Provider Helper
    credprovhost.dll           10.0.19041.2673                 
    credprovs.dll              10.0.19041.2075               
    credprovslegacy.dll        10.0.19041.2673                
    credssp.dll                10.0.19041.1766             Credential Delegation Security Package
    credui.dll                 10.0.19041.2788             Credential Manager User Interface
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                10.0.19041.2965             API32 
    cryptbase.dll              10.0.19041.546              Base cryptographic API DLL
    cryptdlg.dll               10.0.19041.1                Microsoft Common Certificate Dialogs
    cryptdll.dll               10.0.19041.546              Cryptography Manager
    cryptext.dll               10.0.19041.746                
    cryptnet.dll               10.0.19041.906              Crypto Network Related API
    cryptngc.dll               10.0.19041.1566             API  Microsoft Passport
    cryptowinrt.dll            10.0.19041.746              Crypto WinRT Library
    cryptsp.dll                10.0.19041.546              Cryptographic Service Provider API
    crypttpmeksvc.dll          10.0.19041.2546             Cryptographic TPM Endorsement Key Services
    cryptui.dll                10.0.19041.2486               
    cryptuiwizard.dll          10.0.19041.804                 (Microsoft)
    cryptxml.dll               10.0.19041.1                API- XML DigSig
    cscapi.dll                 10.0.19041.546              Offline Files Win32 API
    cscdll.dll                 10.0.19041.546              Offline Files Temporary Shim
    cscobj.dll                 10.0.19041.746               COM-   CSC API
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    d2d1.dll                   10.0.19041.546               Microsoft D2D
    d3d10.dll                  10.0.19041.1                Direct3D 10 Runtime
    d3d10_1.dll                10.0.19041.1                Direct3D 10.1 Runtime
    d3d10_1core.dll            10.0.19041.1                Direct3D 10.1 Runtime
    d3d10core.dll              10.0.19041.1                Direct3D 10 Runtime
    d3d10level9.dll            10.0.19041.1                Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              10.0.19041.2788             Direct3D Rasterizer
    d3d11.dll                  10.0.19041.2913             Direct3D 11 Runtime
    d3d11on12.dll              10.0.19041.1081             Direct3D 11On12 Runtime
    d3d12.dll                  10.0.19041.1266             Direct3D 12 Runtime
    d3d12core.dll              10.0.19041.1266             Direct3D 12 Core Runtime
    d3d8.dll                   10.0.19041.1                Microsoft Direct3D
    d3d8thk.dll                10.0.19041.2788             Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   10.0.19041.2788             Direct3D 9 Runtime
    d3d9on12.dll               10.0.19041.2913             Direct3D9 DDI to Direct3D12 API Mapping Layer
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcompiler_47.dll         10.0.19041.546              Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  10.0.19041.1                Microsoft Direct3D
    d3dim700.dll               10.0.19041.1                Microsoft Direct3D
    d3dramp.dll                10.0.19041.1                Microsoft Direct3D
    d3dscache.dll              10.0.19041.746                  D3D Microsoft (R)
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 10.0.19041.1                DirectX Files DLL
    dabapi.dll                 10.0.19041.1202             Desktop Activity Broker API
    daotpcredentialprovider.dll  10.0.19041.1                  ,    DirectAccess
    dataclen.dll               10.0.19041.1889                Windows
    dataexchange.dll           10.0.19041.1387             Data exchange
    davclnt.dll                10.0.19041.546              Web DAV Client DLL
    davhlpr.dll                10.0.19041.546              DAV Helper DLL
    davsyncprovider.dll        10.0.19041.746              DAV sync engine for contacts, calendar
    daxexec.dll                10.0.19041.2913             daxexec
    dbgcore.dll                10.0.19041.2788             Windows Core Debugging Helpers
    dbgeng.dll                 10.0.19041.1503             Windows Symbolic Debugger Engine
    dbghelp.dll                10.0.19041.1052             Windows Image Helper
    dbgmodel.dll               10.0.19041.1503             Windows Debugger Data Model
    dbnetlib.dll               10.0.19041.844              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               10.0.19041.1                Named Pipes Net DLL for SQL Clients
    dciman32.dll               10.0.19041.2075             DCI Manager
    dcomp.dll                  10.0.19041.2913             Microsoft DirectComposition Library
    ddaclsys.dll               10.0.19041.1                SysPrep module for Resetting Data Drive ACL 
    ddisplay.dll               10.0.19041.746              DirectDisplay
    ddoiproxy.dll              10.0.19041.1                DDOI Interface Proxy
    ddores.dll                 10.0.19041.1                    
    ddraw.dll                  10.0.19041.1                Microsoft DirectDraw
    ddrawex.dll                10.0.19041.1                Direct Draw Ex
    defaultdevicemanager.dll   10.0.19041.1                Default Device Manager
    defaultprinterprovider.dll  10.0.19041.1806               Microsoft Windows  
    delegatorprovider.dll      10.0.19041.1                WMI PassThru Provider for Storage Management
    desktopshellappstatecontract.dll  10.0.19041.746              Desktop Switcher Data Model
    devdispitemprovider.dll    10.0.19041.546               DeviceItem inproc devquery
    devenum.dll                10.0.19041.746               .
    deviceaccess.dll           10.0.19041.2311             Device Broker And Policy COM Server
    deviceassociation.dll      10.0.19041.1                Device Association Client DLL
    devicecenter.dll           10.0.19041.746                
    devicecredential.dll       10.0.19041.1                Microsoft Companion Authenticator Client
    devicedisplaystatusmanager.dll  10.0.19041.746                 
    deviceflows.datamodel.dll  10.0.19041.906              DeviceFlows DataModel
    devicengccredprov.dll      10.0.19041.1202                        ()
    devicepairing.dll          10.0.19041.746               ,   
    devicepairingfolder.dll    10.0.19041.746                 
    devicepairingproxy.dll     10.0.19041.1                Device Pairing Proxy Dll
    devicereactivation.dll     10.0.19041.1865             DeviceReactivation
    devicesetupstatusprovider.dll  10.0.19041.746              DLL    
    deviceuxres.dll            10.0.19041.1                Windows Device User Experience Resource File
    devmgr.dll                 10.0.19041.1566                
    devobj.dll                 10.0.19041.1620             Device Information Set DLL
    devrtl.dll                 10.0.19041.1620             Device Management Run Time Library
    dfscli.dll                 10.0.19041.1                Windows NT Distributed File System Client DLL
    dfshim.dll                 10.0.19041.30000            ClickOnce Application Deployment Support Library
    dfsshlex.dll               10.0.19041.746                   DFS
    dhcpcmonitor.dll           10.0.19041.1                 (DLL)   DHCP
    dhcpcore.dll               10.0.19041.2673              DHCP-
    dhcpcore6.dll              10.0.19041.2673              DHCPv6
    dhcpcsvc.dll               10.0.19041.2673              DHCP-
    dhcpcsvc6.dll              10.0.19041.2673              DHCPv6
    dhcpsapi.dll               10.0.19041.1466              API  DHCP-c
    diagnosticdataquery.dll    10.0.19041.1                Microsoft Windows Diagnostic data Helper API
    diagnosticinvoker.dll      10.0.19041.1081             Microsoft Windows operating system.
    dialclient.dll             10.0.19041.746              DIAL DLL
    dialogblockerproc.dll      10.0.19041.844              Shared process library for DialogBlocker
    dictationmanager.dll       10.0.0.1                     
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                10.0.19041.1                 DLL  DIMS
    dimsroam.dll               10.0.19041.2006              DLL  DIMS  
    dinput.dll                 10.0.19041.1                Microsoft DirectInput
    dinput8.dll                10.0.19041.1                Microsoft DirectInput
    direct2ddesktop.dll        10.0.19041.1                Microsoft Direct2D Desktop Components
    directmanipulation.dll     10.0.19041.1566             Microsoft Direct Manipulation Component
    directml.dll               1.0.2007.1310               DirectML Library
    dismapi.dll                10.0.19041.746              DISM API Framework
    dispbroker.dll             10.0.19041.1151             Display Broker API
    dispex.dll                 5.812.10240.16384           Microsoft  DispEx
    display.dll                10.0.19041.746                
    displaymanager.dll         10.0.19041.746              DisplayManager
    dlnashext.dll              10.0.19041.1949             DLNA Namespace DLL
    dmalertlistener.proxystub.dll  10.0.19041.2788             ProxyStub for DeviceManagment Alert
    dmapisetextimpldesktop.dll  10.0.19041.2193             DmApiSetExtImplDesktop
    dmappsres.dll              10.0.19041.2546             DMAppsRes
    dmband.dll                 10.0.19041.2728             Microsoft DirectMusic Band
    dmcfgutils.dll             10.0.19041.2673             dmcfgutils
    dmcmnutils.dll             10.0.19041.2913             dmcmnutils
    dmcommandlineutils.dll     10.0.19041.1                dmcommandlineutils
    dmcompos.dll               10.0.19041.2728             Microsoft DirectMusic Composer
    dmdlgs.dll                 10.0.19041.1                Disk Management Snap-in Dialogs
    dmdskmgr.dll               10.0.19041.1                Disk Management Snap-in Support Library
    dmdskres.dll               10.0.19041.1                   
    dmdskres2.dll              10.0.19041.1                   
    dmenrollengine.dll         10.0.19041.2846             Enroll Engine DLL
    dmime.dll                  10.0.19041.2728             Microsoft DirectMusic Interactive Engine
    dmintf.dll                 10.0.19041.1                Disk Management DCOM Interface Stub
    dmiso8601utils.dll         10.0.19041.546              dmiso8601utils
    dmloader.dll               10.0.19041.2728             Microsoft DirectMusic Loader
    dmocx.dll                  10.0.19041.1566             TreeView OCX
    dmoleaututils.dll          10.0.19041.1                dmoleaututils
    dmprocessxmlfiltered.dll   10.0.19041.1                dmprocessxmlfiltered
    dmpushproxy.dll            10.0.19041.2193             dmpushproxy
    dmrcdecoder.dll            1.1.2.0                     Digimarc Decoder 4/2/2021
    dmscript.dll               10.0.19041.2728             Microsoft DirectMusic Scripting
    dmstyle.dll                10.0.19041.2728             Microsoft DirectMusic Style Engline
    dmsynth.dll                10.0.19041.2728             Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 10.0.19041.2728               Microsoft DirectMusic
    dmutil.dll                 10.0.19041.1                   
    dmvdsitf.dll               10.0.19041.1                Disk Management Snap-in Support Library
    dmxmlhelputils.dll         10.0.19041.2546             dmxmlhelputils
    dnsapi.dll                 10.0.19041.2546               API DNS-
    dnscmmc.dll                10.0.19041.1                 DLL  DNS  MMC
    docprop.dll                10.0.19041.1                  OLE
    dolbydecmft.dll            10.0.19041.2913             Media Foundation Dolby Digital Atmos Decoders
    dot3api.dll                10.0.19041.746              802.3 Autoconfiguration API
    dot3cfg.dll                10.0.19041.1266              Netsh  802.3
    dot3dlg.dll                10.0.19041.746                UI  802.3
    dot3gpclnt.dll             10.0.19041.1                     802.3
    dot3gpui.dll               10.0.19041.746               "   802.3"
    dot3hc.dll                 10.0.19041.746                 Dot3
    dot3msm.dll                10.0.19041.546                   802.3
    dot3ui.dll                 10.0.19041.1                  802.3
    dpapi.dll                  10.0.19041.546              Data Protection API
    dpapiprovider.dll          10.0.19041.2006             dpapiprovider DLL
    dplayx.dll                 10.0.19041.1                Microsoft DirectPlay
    dpmodemx.dll               10.0.19041.1                        DirectPlay
    dpnaddr.dll                10.0.19041.1                Microsoft DirectPlay8 Address
    dpnathlp.dll               10.0.19041.1                Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  10.0.19041.1                Microsoft DirectPlay
    dpnhpast.dll               10.0.19041.1                Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               10.0.19041.1                Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               10.0.19041.1                Microsoft DirectPlay8 Lobby
    dpwsockx.dll               10.0.19041.1                    TCP/IP  IPX  DirectPlay
    dpx.dll                    10.0.19041.1                Microsoft(R) Delta Package Expander
    dragdropexperiencecommon.dll  10.0.19041.746              In-Proc WinRT server for Windows.Internal.PlatformExtensions.DragDropExperienceCommon
    dragdropexperiencedataexchangedelegated.dll  10.0.19041.746              In-Proc WinRT server for Windows.Internal.PlatformExtensions.DragDropExperienceDataExchangeDelegated
    drprov.dll                 10.0.19041.546                   ,        ()
    drt.dll                    10.0.19041.1                  
    drtprov.dll                10.0.19041.1                Distributed Routing Table Providers
    drttransport.dll           10.0.19041.1                Distributed Routing Table Transport Provider
    drvsetup.dll               10.0.19041.1865             Microsoft (R) Driver Setup
    drvstore.dll               10.0.19041.2546             Driver Store API
    dsauth.dll                 10.0.19041.1                DS Authorization for Services
    dsccoreconfprov.dll        6.2.9200.16384              DSC
    dsclient.dll               10.0.19041.1                Data Sharing Service Client DLL
    dsdmo.dll                  10.0.19041.2728             DirectSound Effects
    dskquota.dll               10.0.19041.1                 DLL    Windows
    dskquoui.dll               10.0.19041.1                 DLL   
    dsound.dll                 10.0.19041.2728             DirectSound
    dsparse.dll                10.0.19041.2486             Active Directory Domain Services API
    dsprop.dll                 10.0.19041.2788               Active Directory
    dsquery.dll                10.0.19041.1                   
    dsreg.dll                  10.0.19041.2075                 AD/AAD
    dsregtask.dll              10.0.19041.2075               DSREG
    dsrole.dll                 10.0.19041.546              DS Setup Client DLL
    dssec.dll                  10.0.19041.1                   
    dssenh.dll                 10.0.19041.1052             Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsui.dll                   10.0.19041.746                  
    dsuiext.dll                10.0.19041.1                   
    dswave.dll                 10.0.19041.2728             Microsoft DirectMusic Wave
    dtsh.dll                   10.0.19041.746               API     
    dui70.dll                  10.0.19041.746               DirectUI Windows
    duser.dll                  10.0.19041.546              Windows DirectUser Engine
    dusmapi.dll                10.0.19041.546              Data Usage API
    dwmapi.dll                 10.0.19041.746               API     ()
    dwrite.dll                 10.0.19041.1566              Microsoft DirectX Typography
    dxcore.dll                 10.0.19041.546              DXCore
    dxdiagn.dll                10.0.19041.2075               Microsoft DirectX
    dxgi.dll                   10.0.19041.2311             DirectX Graphics Infrastructure
    dxilconv.dll               10.0.19041.1                DirectX IL Converter DLL
    dxmasf.dll                 12.0.19041.1266             Microsoft Windows Media Component Removal File.
    dxptasksync.dll            10.0.19041.423               Microsoft Windows DXP
    dxtmsft.dll                11.0.19041.746              DirectX Media -- Image DirectX Transforms
    dxtrans.dll                11.0.19041.746              DirectX Media -- DirectX Transform Core
    dxva2.dll                  10.0.19041.1                DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               10.0.19041.1266             Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                10.0.19041.1266             Eap Peer Config
    eappgnui.dll               10.0.19041.1266                EAP
    eapphost.dll               10.0.19041.2075                EAPHost 
    eappprxy.dll               10.0.19041.546              Microsoft EAPHost Peer Client DLL
    eapprovp.dll               10.0.19041.2604             EAP extension DLL
    eapputil.dll               10.0.19041.746              EAP Private Utility DLL
    eapsimextdesktop.dll       10.0.19041.746               DLL  EXT SIM EAP
    eapteapconfig.dll          10.0.19041.1566             EAP Teap Config DLL
    eapteapext.dll             10.0.19041.1                 DLL    EAP Teap
    easwrt.dll                 10.0.19041.746              Exchange ActiveSync Windows Runtime DLL
    edgehtml.dll               11.0.19041.2965             - Microsoft Edge
    edgeiso.dll                11.0.19041.2965             Isolation Library for edgehtml hosts
    edgemanager.dll            11.0.19041.2075             Microsoft Edge Manager
    editbuffertesthook.dll     10.0.19041.2913             "EditBufferTestHook.DYNLINK"
    editionupgradehelper.dll   10.0.19041.1865             EDITIONUPGRADEHELPER.DLL
    editionupgrademanagerobj.dll  10.0.19041.1865               Windows
    edpauditapi.dll            10.0.19041.1                EDP Audit API
    edputil.dll                10.0.19041.546                EDP
    efsadu.dll                 10.0.19041.1                  
    efsext.dll                 10.0.19041.1023             EFSEXT.DLL
    efsutil.dll                10.0.19041.1                EFS Utility Library
    efswrt.dll                 10.0.19041.1865             Storage Protection Windows Runtime DLL
    ehstorapi.dll              10.0.19041.746              Windows Enhanced Storage API
    ehstorpwdmgr.dll           10.0.19041.1                  Microsoft Enhanced Storage
    els.dll                    10.0.19041.1                  
    elscore.dll                10.0.19041.746               DLL   Els
    elshyph.dll                10.0.19041.1                ELS Hyphenation Service
    elslad.dll                 10.0.19041.1                ELS Language Detection
    elstrans.dll               10.0.19041.1                ELS Transliteration Service
    emailapis.dll              10.0.19041.746              DLL for EmailRT
    embeddedmodesvcapi.dll     10.0.19041.746              Embedded Mode Service Client DLL
    encapi.dll                 10.0.19041.1                Encoder API
    enrollmentapi.dll          10.0.19041.2846             Legacy Phone Enrollment API BackCompat Shim
    enterpriseappmgmtclient.dll  10.0.19041.2788             EnterpriseAppMgmtClient.dll
    enterpriseresourcemanager.dll  10.0.19041.2788             enterpriseresourcemanager DLL
    eqossnap.dll               10.0.19041.1                  EQoS
    errordetails.dll           10.0.19041.1320             Microsoft Windows operating system.
    errordetailscore.dll       10.0.19041.1                Microsoft Windows operating system.
    es.dll                     2001.12.10941.16384         COM+
    esdsip.dll                 10.0.19041.2846             Crypto SIP provider for signing and verifying .esd Electronic Software Distribution files
    esent.dll                  10.0.19041.2788                 ESE  Microsoft(R) Windows(R)
    esentprf.dll               10.0.19041.1                Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    esevss.dll                 10.0.19041.1                Microsoft(R) ESENT shadow utilities
    etwcoreuicomponentsresources.dll  10.0.19041.1                Microsoft CoreComponents UI ETW manifest Dll
    etweseproviderresources.dll  10.0.19041.1                Microsoft ESE ETW
    etwrundown.dll             10.0.19041.1                Etw Rundown Helper Library
    eventcls.dll               10.0.19041.746              Microsoft Volume Shadow Copy Service event class
    evr.dll                    10.0.19041.546                DLL   
    execmodelclient.dll        10.0.19041.1566             ExecModelClient
    execmodelproxy.dll         10.0.19041.546              ExecModelProxy
    explorerframe.dll          10.0.19041.1949             ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    exsmime.dll                10.0.19041.746              LExsmime
    extrasxmlparser.dll        10.0.19041.1                Extras XML parser used to extract extension information from XML
    f3ahvoas.dll               10.0.19041.1                JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    familysafetyext.dll        10.0.19041.1                FamilySafety ChildAccount Extensions
    faultrep.dll               10.0.19041.2546                    Windows
    fdbth.dll                  10.0.19041.1                Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             10.0.19041.1                Bluetooth Provider Proxy Dll
    fddevquery.dll             10.0.19041.746              Microsoft Windows Device Query Helper
    fde.dll                    10.0.19041.746                 
    fdeploy.dll                10.0.19041.1                    
    fdpnp.dll                  10.0.19041.746              Pnp Provider Dll
    fdprint.dll                10.0.19041.1806              DLL    
    fdproxy.dll                10.0.19041.1                Function Discovery Proxy Dll
    fdssdp.dll                 10.0.19041.1806             Function Discovery SSDP Provider Dll
    fdwcn.dll                  10.0.19041.746              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 10.0.19041.746              Function Discovery WNet Provider Dll
    fdwsd.dll                  10.0.19041.1806             Function Discovery WS Discovery Provider Dll
    feclient.dll               10.0.19041.1586             Windows NT File Encryption Client Interfaces
    ffbroker.dll               10.0.19041.746              Force Feedback Broker And Policy COM Server
    fidocredprov.dll           10.0.19041.2788                FIDO
    filemgmt.dll               10.0.19041.746                 
    findnetprinters.dll        10.0.19041.1806             Find Network Printers COM Component
    fingerprintcredential.dll  10.0.19041.1081                 WinBio
    firewallapi.dll            10.0.19041.2913             API   Windows
    firewallcontrolpanel.dll   10.0.19041.746                  Windows
    flightsettings.dll         10.0.19041.2546               
    fltlib.dll                 10.0.19041.546               
    fmifs.dll                  10.0.19041.1                FM IFS Utility DLL
    fms.dll                    10.0.19041.1                  
    fontext.dll                10.0.19041.423                Windows
    fontglyphanimator.dll      10.0.19041.746              Font Glyph Animator
    fontsub.dll                10.0.19041.2075             Font Subsetting DLL
    fphc.dll                   10.0.19041.964               Filtering Platform Helper
    framedyn.dll               10.0.19041.1                WMI SDK Provider Framework
    framedynos.dll             10.0.19041.1320             WMI SDK Provider Framework
    frameserverclient.dll      10.0.19041.2673             Frame Server Client DLL
    frprov.dll                 10.0.19041.1                Folder Redirection WMI Provider
    fsutilext.dll              10.0.19041.1                FS Utility Extension DLL
    fundisc.dll                10.0.19041.1                DLL  
    fveapi.dll                 10.0.19041.2788             Windows BitLocker Drive Encryption API
    fveapibase.dll             10.0.19041.2788             Windows BitLocker Drive Encryption Base API
    fvecerts.dll               10.0.19041.1                BitLocker Certificates Library
    fvsdk_x86.dll                                          
    fwbase.dll                 10.0.19041.2913             Firewall Base DLL
    fwcfg.dll                  10.0.19041.2913                  Windows
    fwpolicyiomgr.dll          10.0.19041.2913             FwPolicyIoMgr DLL
    fwpuclnt.dll               10.0.19041.2913             API   FWP/IPsec
    fwremotesvr.dll            10.0.19041.1682             Windows Defender Firewall Remote APIs Server
    fxsapi.dll                 10.0.19041.2604             Microsoft  Fax API Support DLL
    fxscom.dll                 10.0.19041.2604             Microsoft Fax Server COM Client Interface
    fxscomex.dll               10.0.19041.2604             Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               10.0.19041.1586             Microsoft  Fax Exchange Command Extension
    fxsresm.dll                10.0.19041.2604              DLL   (Microsoft)
    fxsxp32.dll                10.0.19041.1889             Microsoft  Fax Transport Provider
    gamebarpresencewriter.proxy.dll  10.0.19041.1741             GameBar Presence Writer Proxy
    gamechatoverlayext.dll     10.0.19041.1                GameChat Overlay Extension
    gamechattranscription.dll  10.0.19041.746              GameChatTranscription
    gameinput.dll              0.1908.19041.2965           GameInput API
    gamemode.dll               10.0.19041.1                Game Mode Client
    gamepanelexternalhook.dll  10.0.19041.1                GamePanelExternalHook.dll
    gameux.dll                 10.0.19041.746              Games Explorer
    gamingtcui.dll             10.0.19041.746              Windows Gaming Internal CallableUI dll
    gcdef.dll                  10.0.19041.1                     
    gdi32.dll                  10.0.19041.2913             GDI Client DLL
    gdi32full.dll              10.0.19041.2965             GDI Client DLL
    gdiplus.dll                10.0.19041.2251             Microsoft GDI+
    geocommon.dll              10.0.19041.746              Geocommon
    geolocation.dll            10.0.19041.746               DLL    
    getuname.dll               10.0.19041.1                Unicode name Dll for UCE
    glmf32.dll                 10.0.19041.488              OpenGL Metafiling DLL
    globinputhost.dll          10.0.19041.1806             Windows Globalization Extension API for Input
    glu32.dll                  10.0.19041.2193               OpenGL
    gmsaclient.dll             10.0.19041.1466             "gmsaclient.DYNLINK"
    gnsdk_fp.dll               3.9.511.0                   Gracenote SDK component
    gpapi.dll                  10.0.19041.2673               API  
    gpedit.dll                 10.0.19041.2251             GPEdit
    gpprefcl.dll               10.0.19041.2251                
    gpprnext.dll               10.0.19041.1806                
    gpscript.dll               10.0.19041.572                
    gptext.dll                 10.0.19041.1                GPTExt
    graphicscapture.dll        10.0.19041.2673             Microsoft Windows Graphics Capture Api
    hbaapi.dll                 10.0.19041.1                HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            10.0.19041.1                  "   "
    hdcphandler.dll            10.0.19041.746              Hdcp Handler DLL
    heatcore.dll                                           
    helppaneproxy.dll          10.0.19041.746              Microsoft Help Proxy
    hgcpl.dll                  10.0.19041.1865                
    hhsetup.dll                10.0.19041.1                Microsoft HTML Help
    hid.dll                    10.0.19041.546                HID
    hidserv.dll                10.0.19041.1                   HID
    hlink.dll                  10.0.19041.2673              Microsoft Office 2000
    hmkd.dll                   10.0.19041.1                Windows HMAC Key Derivation API
    hnetcfg.dll                10.0.19041.746                 
    hnetcfgclient.dll          10.0.19041.746               API   
    hnetmon.dll                10.0.19041.1                DLL   
    holoshellruntime.dll       10.0.19041.746              Hologram Shell Runtime
    hrtfapo.dll                10.0.19041.1865             HrtfApo.dll
    httpapi.dll                10.0.19041.1110             HTTP Protocol Stack API
    htui.dll                   10.0.19041.1                    
    hvsimanagementapi.dll                                  
    ia2comproxy.dll            10.0.19041.1                IAccessible2 COM Proxy Stub DLL
    ias.dll                    10.0.19041.2251                (NPS)
    iasacct.dll                10.0.19041.2251               NPS
    iasads.dll                 10.0.19041.1466               Active Directory NPS
    iasdatastore.dll           10.0.19041.746              NPS Datastore server
    iashlpr.dll                10.0.19041.746                NPS
    iasmigplugin.dll           10.0.19041.746              NPS Migration DLL
    iasnap.dll                 10.0.19041.746              NPS NAP Provider
    iaspolcy.dll               10.0.19041.2251             NPS Pipeline
    iasrad.dll                 10.0.19041.2251               RADIUS NPS
    iasrecst.dll               10.0.19041.746              NPS XML Datastore Access
    iassam.dll                 10.0.19041.1466             NPS NT SAM Provider
    iassdo.dll                 10.0.19041.746               SDO NPS
    iassvcs.dll                10.0.19041.1503               NPS
    iccvid.dll                 1.10.0.12                    Cinepak
    icm32.dll                  10.0.19041.546              Microsoft Color Management Module (CMM)
    icmp.dll                   10.0.19041.1                ICMP DLL
    icmui.dll                  10.0.19041.1                    
    iconcodecservice.dll       10.0.19041.1                Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 10.0.19041.1                   
    icu.dll                    64.2.0.0                    ICU Combined Library
    icuin.dll                  64.2.0.0                    ICU I18N Forwarder DLL
    icuuc.dll                  64.2.0.0                    ICU Common Forwarder DLL
    idctrls.dll                10.0.19041.746               
    idndl.dll                  10.0.19041.1                Downlevel DLL
    idstore.dll                10.0.19041.746              Identity Store
    ieadvpack.dll              11.0.19041.1                ADVPACK
    ieapfltr.dll               11.0.19041.1566             Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.19041.2546               IEAK
    ieframe.dll                11.0.19041.2913             
    iemigplugin.dll            11.0.19041.2913             IE Migration Plugin
    iepeers.dll                11.0.19041.1949             Peer- Internet Explorer
    ieproxy.dll                11.0.19041.2913             IE ActiveX Interface Marshaling Library
    iernonce.dll               11.0.19041.1                  RunOnce   
    iertutil.dll               11.0.19041.2965                  Internet Explorer
    iesetup.dll                11.0.19041.1                  IOD
    iesysprep.dll              11.0.19041.1                IE Sysprep Provider
    ieui.dll                   11.0.19041.1                   Internet Explorer
    ifmon.dll                  10.0.19041.1                  IF
    ifsutil.dll                10.0.19041.1266             IFS Utility DLL
    ifsutilx.dll               10.0.19041.1                IFS Utility Extension DLL
    imagehlp.dll               10.0.19041.1415             Windows NT Image Helper
    imageres.dll               10.0.19041.1                Windows Image Resource
    imagesp1.dll               10.0.19041.1                Windows SP1 Image Resource
    imapi.dll                  10.0.19041.2913              Image Mastering API
    imapi2.dll                 10.0.19041.746              IMAPI  2
    imapi2fs.dll               10.0.19041.1266             Image Mastering File System Imaging API v2
    imgutil.dll                11.0.19041.746              IE plugin image decoder support DLL
    imm32.dll                  10.0.19041.2673             Multi-User Windows IMM32 API Client DLL
    indexeddblegacy.dll        10.0.19041.2673             "IndexedDbLegacy.DYNLINK"
    inetcomm.dll               10.0.19041.928              Microsoft Internet Messaging API Resources
    inetmib1.dll               10.0.19041.1                Microsoft MIB-II subagent
    inetres.dll                10.0.19041.928               API  
    inked.dll                  10.0.19041.1586             Microsoft Tablet PC InkEdit Control
    inkobjcore.dll             10.0.19041.746                    (Microsoft)
    input.dll                  10.0.19041.1320              DLL  
    inputhost.dll              10.0.19041.1741             InputHost
    inputinjectionbroker.dll   10.0.19041.746              Broker for WinRT input injection.
    inputswitch.dll            10.0.19041.1741               Microsoft Windows
    inseng.dll                 11.0.19041.1                 
    installservice.dll         10.0.19041.2913             InstallService
    installservicetasks.dll    10.0.19041.2913             InstallService Tasks
    iologmsg.dll               10.0.19041.1                  /
    ipeloggingdictationhelper.dll  1.0.0.1                     IPE Logging Library Helper
    iphlpapi.dll               10.0.19041.2788             API   IP
    ipnathlpclient.dll         10.0.19041.1                   IP NAT
    iprop.dll                  10.0.19041.1                OLE PropertySet Implementation
    iprtprio.dll               10.0.19041.1320             IP Routing Protocol Priority DLL
    iprtrmgr.dll               10.0.19041.1320              IP-
    ipsecsnp.dll               10.0.19041.746                 IP-
    ipsmsnap.dll               10.0.19041.746                IP-
    ir32_32.dll                10.0.19041.1                IR32_32 WRAPPER DLL
    ir32_32original.dll        3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_32original.dll        4.51.16.3                   Intel Indeo Video 4.5
    ir41_qc.dll                10.0.19041.1                IR41_QC WRAPPER DLL
    ir41_qcoriginal.dll        4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               10.0.19041.1                IR41_QCX WRAPPER DLL
    ir41_qcxoriginal.dll       4.30.64.1                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                10.0.19041.1                IR50_32 WRAPPER DLL
    ir50_32original.dll        5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                10.0.19041.1                IR50_QC WRAPPER DLL
    ir50_qcoriginal.dll        5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               10.0.19041.1                IR50_QCX WRAPPER DLL
    ir50_qcxoriginal.dll       5.0.64.48                   Intel Indeo video 5.10 Quick Compressor
    iri.dll                    10.0.19041.546              iri
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               10.0.19041.1766             API-  iSCSI
    iscsied.dll                10.0.19041.1766             iSCSI Extension DLL
    iscsium.dll                10.0.19041.1766             iSCSI Discovery api
    iscsiwmi.dll               10.0.19041.1766             MS iSCSI Initiator WMI Provider
    iscsiwmiv2.dll             10.0.19041.1766             WMI Provider for iSCSI
    itircl.dll                 10.0.19041.746              Microsoft InfoTech IR Local DLL
    itss.dll                   10.0.19041.1                Microsoft InfoTech Storage System Library
    iyuv_32.dll                10.0.19041.1                Intel Indeo(R) Video YUV 
    javascriptcollectionagent.dll  11.0.19041.746              JavaScript Performance Collection Agent
    joinproviderol.dll         10.0.19041.2913                DLL- 
    joinutil.dll               10.0.19041.2913             Join Utility DLL
    jpmapcontrol.dll           10.0.19041.746              Jupiter Map Control
    jscript.dll                5.812.10240.16384           Microsoft  JScript
    jscript9.dll               11.0.19041.2673             Microsoft  JScript
    jscript9diag.dll           11.0.19041.2673             Microsoft  JScript Diagnostics
    jsproxy.dll                11.0.19041.2193             JScript Proxy Auto-Configuration
    kbd101.dll                 10.0.19041.662              JP Japanese Keyboard Layout for 101
    kbd101a.dll                10.0.19041.1                KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                10.0.19041.1                KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                10.0.19041.1                KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 10.0.19041.1                KO Hangeul Keyboard Layout for 103
    kbd106.dll                 10.0.19041.662              JP Japanese Keyboard Layout for 106
    kbd106n.dll                10.0.19041.662              JP Japanese Keyboard Layout for 106
    kbda1.dll                  10.0.19041.1                Arabic_English_101 Keyboard Layout
    kbda2.dll                  10.0.19041.1                Arabic_2 Keyboard Layout
    kbda3.dll                  10.0.19041.1                Arabic_French_102 Keyboard Layout
    kbdadlm.dll                10.0.19041.1                Adlam Keyboard Layout
    kbdal.dll                  10.0.19041.1                Albania Keyboard Layout
    kbdarme.dll                10.0.19041.1                Eastern Armenian Keyboard Layout
    kbdarmph.dll               10.0.19041.1                Armenian Phonetic Keyboard Layout
    kbdarmty.dll               10.0.19041.1                Armenian Typewriter Keyboard Layout
    kbdarmw.dll                10.0.19041.1                Western Armenian Keyboard Layout
    kbdax2.dll                 10.0.19041.1                JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 10.0.19041.1                Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                10.0.19041.1                Azeri-Latin Keyboard Layout
    kbdazst.dll                10.0.19041.1                Azerbaijani (Standard) Keyboard Layout
    kbdbash.dll                10.0.19041.1                Bashkir Keyboard Layout
    kbdbe.dll                  10.0.19041.1                Belgian Keyboard Layout
    kbdbene.dll                10.0.19041.1                Belgian Dutch Keyboard Layout
    kbdbgph.dll                10.0.19041.1                Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               10.0.19041.1                Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 10.0.19041.1                Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 10.0.19041.1                Belarusian Keyboard Layout
    kbdbr.dll                  10.0.19041.1                Brazilian Keyboard Layout
    kbdbu.dll                  10.0.19041.1                Bulgarian (Typewriter) Keyboard Layout
    kbdbug.dll                 10.0.19041.1                Buginese Keyboard Layout
    kbdbulg.dll                10.0.19041.1                Bulgarian Keyboard Layout
    kbdca.dll                  10.0.19041.1                Canadian Multilingual Keyboard Layout
    kbdcan.dll                 10.0.19041.1                Canadian Multilingual Standard Keyboard Layout
    kbdcher.dll                10.0.19041.1                Cherokee Nation Keyboard Layout
    kbdcherp.dll               10.0.19041.1                Cherokee Phonetic Keyboard Layout
    kbdcr.dll                  10.0.19041.1                Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  10.0.19041.1                Czech Keyboard Layout
    kbdcz1.dll                 10.0.19041.1                Czech_101 Keyboard Layout
    kbdcz2.dll                 10.0.19041.1                Czech_Programmer's Keyboard Layout
    kbdda.dll                  10.0.19041.1                Danish Keyboard Layout
    kbddiv1.dll                10.0.19041.1                Divehi Phonetic Keyboard Layout
    kbddiv2.dll                10.0.19041.1                Divehi Typewriter Keyboard Layout
    kbddv.dll                  10.0.19041.1                Dvorak US English Keyboard Layout
    kbddzo.dll                 10.0.19041.1                Dzongkha Keyboard Layout
    kbdes.dll                  10.0.19041.1                Spanish Alernate Keyboard Layout
    kbdest.dll                 10.0.19041.1                Estonia Keyboard Layout
    kbdfa.dll                  10.0.19041.1                Persian Keyboard Layout
    kbdfar.dll                 10.0.19041.1                Persian Standard Keyboard Layout
    kbdfc.dll                  10.0.19041.1                Canadian French Keyboard Layout
    kbdfi.dll                  10.0.19041.1                Finnish Keyboard Layout
    kbdfi1.dll                 10.0.19041.1                Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  10.0.19041.1                F?roese Keyboard Layout
    kbdfr.dll                  10.0.19041.1                French Keyboard Layout
    kbdfthrk.dll               10.0.19041.1                Futhark Keyboard Layout
    kbdgae.dll                 10.0.19041.1                Scottish Gaelic (United Kingdom) Keyboard Layout
    kbdgeo.dll                 10.0.19041.1                Georgian Keyboard Layout
    kbdgeoer.dll               10.0.19041.1                Georgian (Ergonomic) Keyboard Layout
    kbdgeome.dll               10.0.19041.1                Georgian (MES) Keyboard Layout
    kbdgeooa.dll               10.0.19041.1                Georgian (Old Alphabets) Keyboard Layout
    kbdgeoqw.dll               10.0.19041.1                Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 10.0.19041.1                Greek_Latin Keyboard Layout
    kbdgn.dll                  10.0.19041.1                Guarani Keyboard Layout
    kbdgr.dll                  10.0.19041.1                German Keyboard Layout
    kbdgr1.dll                 10.0.19041.1                German_IBM Keyboard Layout
    kbdgrlnd.dll               10.0.19041.1                Greenlandic Keyboard Layout
    kbdgthc.dll                10.0.19041.1                Gothic Keyboard Layout
    kbdhau.dll                 10.0.19041.1                Hausa Keyboard Layout
    kbdhaw.dll                 10.0.19041.1                Hawaiian Keyboard Layout
    kbdhe.dll                  10.0.19041.1                Greek Keyboard Layout
    kbdhe220.dll               10.0.19041.1                Greek IBM 220 Keyboard Layout
    kbdhe319.dll               10.0.19041.1                Greek IBM 319 Keyboard Layout
    kbdheb.dll                 10.0.19041.1                KBDHEB Keyboard Layout
    kbdhebl3.dll               10.0.19041.1                Hebrew Standard Keyboard Layout
    kbdhela2.dll               10.0.19041.1                Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               10.0.19041.1                Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                10.0.19041.1                Greek_Polytonic Keyboard Layout
    kbdhu.dll                  10.0.19041.1                Hungarian Keyboard Layout
    kbdhu1.dll                 10.0.19041.1                Hungarian 101-key Keyboard Layout
    kbdibm02.dll               10.0.19041.1                JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 10.0.19041.1                Igbo Keyboard Layout
    kbdic.dll                  10.0.19041.1                Icelandic Keyboard Layout
    kbdinasa.dll               10.0.19041.1                Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               10.0.19041.1                Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               10.0.19041.1                Bengali (Inscript) Keyboard Layout
    kbdinben.dll               10.0.19041.1                Bengali Keyboard Layout
    kbdindev.dll               10.0.19041.1                Devanagari Keyboard Layout
    kbdinen.dll                10.0.19041.1                English (India) Keyboard Layout
    kbdinguj.dll               10.0.19041.1                Gujarati Keyboard Layout
    kbdinhin.dll               10.0.19041.1                Hindi Keyboard Layout
    kbdinkan.dll               10.0.19041.1                Kannada Keyboard Layout
    kbdinmal.dll               10.0.19041.1                Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               10.0.19041.1                Marathi Keyboard Layout
    kbdinori.dll               10.0.19041.1                Odia Keyboard Layout
    kbdinpun.dll               10.0.19041.1                Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               10.0.19041.1                Tamil Keyboard Layout
    kbdintel.dll               10.0.19041.1                Telugu Keyboard Layout
    kbdinuk2.dll               10.0.19041.1                Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  10.0.19041.1                Irish Keyboard Layout
    kbdit.dll                  10.0.19041.1                Italian Keyboard Layout
    kbdit142.dll               10.0.19041.1                Italian 142 Keyboard Layout
    kbdiulat.dll               10.0.19041.1                Inuktitut Latin Keyboard Layout
    kbdjav.dll                 10.0.19041.1                Javanese Keyboard Layout
    kbdjpn.dll                 10.0.19041.662              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 10.0.19041.1                Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                10.0.19041.1                Cambodian Standard Keyboard Layout
    kbdkni.dll                 10.0.19041.1                Khmer (NIDA) Keyboard Layout
    kbdkor.dll                 10.0.19041.1                KO Hangeul Keyboard Layout Stub driver
    kbdkurd.dll                10.0.19041.1                Central Kurdish Keyboard Layout
    kbdkyr.dll                 10.0.19041.1                Kyrgyz Keyboard Layout
    kbdla.dll                  10.0.19041.1                Latin-American Spanish Keyboard Layout
    kbdlao.dll                 10.0.19041.1                Lao Standard Keyboard Layout
    kbdlisub.dll               10.0.19041.1                Lisu Basic Keyboard Layout
    kbdlisus.dll               10.0.19041.1                Lisu Standard Keyboard Layout
    kbdlk41a.dll               10.0.19041.1                DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  10.0.19041.1                Lithuania Keyboard Layout
    kbdlt1.dll                 10.0.19041.1                Lithuanian Keyboard Layout
    kbdlt2.dll                 10.0.19041.1                Lithuanian Standard Keyboard Layout
    kbdlv.dll                  10.0.19041.1                Latvia Keyboard Layout
    kbdlv1.dll                 10.0.19041.1                Latvia-QWERTY Keyboard Layout
    kbdlvst.dll                10.0.19041.1                Latvian (Standard) Keyboard Layout
    kbdmac.dll                 10.0.19041.1                Macedonian (North Macedonia) Keyboard Layout
    kbdmacst.dll               10.0.19041.1                Macedonian (North Macedonia) - Standard Keyboard Layout
    kbdmaori.dll               10.0.19041.1                Maori Keyboard Layout
    kbdmlt47.dll               10.0.19041.1                Maltese 47-key Keyboard Layout
    kbdmlt48.dll               10.0.19041.1                Maltese 48-key Keyboard Layout
    kbdmon.dll                 10.0.19041.1                Mongolian Keyboard Layout
    kbdmonmo.dll               10.0.19041.1                Mongolian (Mongolian Script) Keyboard Layout
    kbdmonst.dll               10.0.19041.1                Traditional Mongolian (Standard) Keyboard Layout
    kbdmyan.dll                10.0.19041.1                Myanmar Keyboard Layout
    kbdne.dll                  10.0.19041.1                Dutch Keyboard Layout
    kbdnec.dll                 10.0.19041.1                JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               10.0.19041.1                JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               10.0.19041.1                JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               10.0.19041.1                JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                10.0.19041.1                Nepali Keyboard Layout
    kbdnko.dll                 10.0.19041.1                N'Ko Keyboard Layout
    kbdno.dll                  10.0.19041.1                Norwegian Keyboard Layout
    kbdno1.dll                 10.0.19041.1                Norwegian with Sami Keyboard Layout
    kbdnso.dll                 10.0.19041.1                Sesotho sa Leboa Keyboard Layout
    kbdntl.dll                 10.0.19041.1                New Tai Leu Keyboard Layout
    kbdogham.dll               10.0.19041.1                Ogham Keyboard Layout
    kbdolch.dll                10.0.19041.1                Ol Chiki Keyboard Layout
    kbdoldit.dll               10.0.19041.1                Old Italic Keyboard Layout
    kbdosa.dll                 10.0.19041.1                Osage Keyboard Layout
    kbdosm.dll                 10.0.19041.1                Osmanya Keyboard Layout
    kbdpash.dll                10.0.19041.1                Pashto (Afghanistan) Keyboard Layout
    kbdphags.dll               10.0.19041.1                Phags-pa Keyboard Layout
    kbdpl.dll                  10.0.19041.1                Polish Keyboard Layout
    kbdpl1.dll                 10.0.19041.1                Polish Programmer's Keyboard Layout
    kbdpo.dll                  10.0.19041.1                Portuguese Keyboard Layout
    kbdro.dll                  10.0.19041.1                Romanian (Legacy) Keyboard Layout
    kbdropr.dll                10.0.19041.1                Romanian (Programmers) Keyboard Layout
    kbdrost.dll                10.0.19041.1                Romanian (Standard) Keyboard Layout
    kbdru.dll                  10.0.19041.1                Russian Keyboard Layout
    kbdru1.dll                 10.0.19041.1                Russia(Typewriter) Keyboard Layout
    kbdrum.dll                 10.0.19041.1                Russian - Mnemonic Keyboard Layout
    kbdsf.dll                  10.0.19041.1                Swiss French Keyboard Layout
    kbdsg.dll                  10.0.19041.1                Swiss German Keyboard Layout
    kbdsl.dll                  10.0.19041.1                Slovak Keyboard Layout
    kbdsl1.dll                 10.0.19041.1                Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               10.0.19041.1                Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               10.0.19041.1                Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 10.0.19041.1                Sinhala Keyboard Layout
    kbdsora.dll                10.0.19041.1                Sora Keyboard Layout
    kbdsorex.dll               10.0.19041.1                Sorbian Extended Keyboard Layout
    kbdsors1.dll               10.0.19041.1                Sorbian Standard Keyboard Layout
    kbdsorst.dll               10.0.19041.1                Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  10.0.19041.1                Spanish Keyboard Layout
    kbdsw.dll                  10.0.19041.1                Swedish Keyboard Layout
    kbdsw09.dll                10.0.19041.1                Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                10.0.19041.1                Syriac Standard Keyboard Layout
    kbdsyr2.dll                10.0.19041.1                Syriac Phoenetic Keyboard Layout
    kbdtaile.dll               10.0.19041.1                Tai Le Keyboard Layout
    kbdtajik.dll               10.0.19041.1                Tajik Keyboard Layout
    kbdtat.dll                 10.0.19041.1                Tatar (Legacy) Keyboard Layout
    kbdth0.dll                 10.0.19041.1                Thai Kedmanee Keyboard Layout
    kbdth1.dll                 10.0.19041.1                Thai Pattachote Keyboard Layout
    kbdth2.dll                 10.0.19041.1                Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 10.0.19041.1                Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtifi.dll                10.0.19041.1                Tifinagh (Basic) Keyboard Layout
    kbdtifi2.dll               10.0.19041.1                Tifinagh (Extended) Keyboard Layout
    kbdtiprc.dll               10.0.19041.1                Tibetan (PRC) Keyboard Layout
    kbdtiprd.dll               10.0.19041.1                Tibetan (PRC) - Updated Keyboard Layout
    kbdtt102.dll               10.0.19041.1                Tatar Keyboard Layout
    kbdtuf.dll                 10.0.19041.1                Turkish F Keyboard Layout
    kbdtuq.dll                 10.0.19041.1                Turkish Q Keyboard Layout
    kbdturme.dll               10.0.19041.1                Turkmen Keyboard Layout
    kbdtzm.dll                 10.0.19041.1                Central Atlas Tamazight Keyboard Layout
    kbdughr.dll                10.0.19041.1                Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               10.0.19041.1                Uyghur Keyboard Layout
    kbduk.dll                  10.0.19041.1                United Kingdom Keyboard Layout
    kbdukx.dll                 10.0.19041.1                United Kingdom Extended Keyboard Layout
    kbdur.dll                  10.0.19041.1                Ukrainian Keyboard Layout
    kbdur1.dll                 10.0.19041.1                Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                10.0.19041.1                Urdu Keyboard Layout
    kbdus.dll                  10.0.19041.546              United States Keyboard Layout
    kbdusa.dll                 10.0.19041.1                US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 10.0.19041.1                Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 10.0.19041.1                Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 10.0.19041.1                US Multinational Keyboard Layout
    kbduzb.dll                 10.0.19041.1                Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                10.0.19041.1                Vietnamese Keyboard Layout
    kbdwol.dll                 10.0.19041.1                Wolof Keyboard Layout
    kbdyak.dll                 10.0.19041.1                Sakha - Russia Keyboard Layout
    kbdyba.dll                 10.0.19041.1                Yoruba Keyboard Layout
    kbdycc.dll                 10.0.19041.1                Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 10.0.19041.1                Serbian (Latin) Keyboard Layout
    kerbclientshared.dll       10.0.19041.1889             Kerberos Client Shared Functionality
    kerberos.dll               10.0.19041.2913               Kerberos
    kernel.appcore.dll         10.0.19041.546              AppModel API Host
    kernel32.dll               10.0.19041.2913               Windows NT BASE API
    kernelbase.dll             10.0.19041.2965               Windows NT BASE API
    keyboardfiltercore.dll     10.0.19041.964              Keyboard Filter Hooks
    keyboardfiltershim.dll     10.0.19041.844              Keyboard Filter AppShim
    keycredmgr.dll             10.0.19041.1202             Microsoft Key Credential Manager
    keyiso.dll                 10.0.19041.2846                CNG
    keymgr.dll                 10.0.19041.1                    
    ksuser.dll                 10.0.19041.1                User CSA Library
    ktmw32.dll                 10.0.19041.546              Windows KTM Win32 Client DLL
    l2gpstore.dll              10.0.19041.1                Policy Storage dll
    l2nacp.dll                 10.0.19041.1                   Onex Windows
    l2sechc.dll                10.0.19041.1706                   2
    languageoverlayutil.dll    10.0.19041.2546             Provides helper APIs for managing overlaid localized Windows resources.
    laprxy.dll                 12.0.19041.1                Windows Media Logagent Proxy
    licensemanager.dll         10.0.19041.1865             LicenseManager
    licensemanagerapi.dll      10.0.19041.906              "LicenseManagerApi.DYNLINK"
    licensingdiagspp.dll       10.0.19041.2311             Licensing Diagnostics SPP Plugin
    licensingwinrt.dll         10.0.19041.2788             LicensingWinRuntime
    licmgr10.dll               11.0.19041.1                 (DLL)    Microsoft
    linkinfo.dll               10.0.19041.546              Windows Volume Tracking
    loadperf.dll               10.0.19041.1                    
    localsec.dll               10.0.19041.2075              MMC "   "
    locationapi.dll            10.0.19041.746              Microsoft Windows Location API
    locationframeworkinternalps.dll  10.0.19041.1                Windows Geolocation Framework Internal PS
    locationframeworkps.dll    10.0.19041.1                Windows Geolocation Framework PS
    lockappbroker.dll          10.0.19041.1741              DLL   "" Windows
    lockscreendata.dll         10.0.19041.746              Windows Lock Screen Data DLL
    loghours.dll               10.0.19041.1                 
    logoncli.dll               10.0.19041.2193             Net Logon Client DLL
    lpk.dll                    10.0.19041.2075             Language Pack
    lsmproxy.dll               10.0.19041.2075             LSM interfaces proxy Dll
    luainstall.dll             10.0.19041.746              Lua manifest install
    luiapi.dll                 10.0.19041.1                LUI API
    lz32.dll                   5.0.1.1                     LZ Expand/Compress API DLL
    magnification.dll          10.0.19041.1                 API  ()
    mapconfiguration.dll       10.0.19041.746              MapConfiguration
    mapcontrolcore.dll         10.0.19041.1                Map Control Core
    mapcontrolstringsres.dll   10.0.19041.1                    
    mapgeocoder.dll            10.0.19041.746              Maps Geocoder
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    maprouter.dll              10.0.19041.2311             Maps Router
    mapsbtsvc.dll              10.0.19041.746              Maps Background Transfer Service
    mbaeapi.dll                10.0.19041.746              API     
    mbaeapipublic.dll          10.0.19041.1620             Mobile Broadband Account API
    mbsmsapi.dll               10.0.19041.746              Microsoft Windows Mobile Broadband SMS API
    mbussdapi.dll              10.0.19041.746              Microsoft Windows Mobile Broadband USSD API
    mccsengineshared.dll       10.0.19041.746              Utilies shared among OneSync engines
    mciavi32.dll               10.0.19041.1                 MCI Video  Windows
    mcicda.dll                 10.0.19041.1                 MCI   cdaudio
    mciqtz32.dll               10.0.19041.1                 MCI DirectShow
    mciseq.dll                 10.0.19041.1                 MCI   MIDI
    mciwave.dll                10.0.19041.1                 MCI   
    mcrecvsrc.dll              10.0.19041.1566             Miracast Media Foundation Source DLL
    mdminst.dll                10.0.19041.1                 
    mdmlocalmanagement.dll     10.0.19041.2673             MDM Local Management DLL
    mdmregistration.dll        10.0.19041.2913             MDM Registration DLL
    messagingdatamodel2.dll    10.0.19041.746              MessagingDataModel2
    mf.dll                     10.0.19041.2486              DLL Media Foundation
    mf3216.dll                 10.0.19041.1466             32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               10.0.19041.1                Media Foundation AAC Encoder
    mfasfsrcsnk.dll            10.0.19041.2788             Media Foundation ASF Source and Sink DLL
    mfaudiocnv.dll             10.0.19041.746              Media Foundation Audio Converter DLL
    mfc100.dll                 10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100u.dll                10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc120.dll                 12.0.21005.1                MFCDLL Shared Library - Retail Version
    mfc120chs.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120cht.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120deu.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120enu.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120esn.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120fra.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120ita.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120jpn.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120kor.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120rus.dll              12.0.21005.1                MFC Language Specific Resources
    mfc120u.dll                12.0.21005.1                MFCDLL Shared Library - Retail Version
    mfc140.dll                 14.36.32532.0               MFCDLL Shared Library - Retail Version
    mfc140chs.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140cht.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140deu.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140enu.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140esn.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140fra.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140ita.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140jpn.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140kor.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140rus.dll              14.36.32532.0               MFC Language Specific Resources
    mfc140u.dll                14.36.32532.0               MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6140                    MFCDLL -  
    mfc40u.dll                 4.1.0.6140                    MFCDLL -  
    mfc42.dll                  6.6.8063.0                    MFCDLL -  
    mfc42u.dll                 6.6.8063.0                    MFCDLL -  
    mfcaptureengine.dll        10.0.19041.1865              DLL Media Foundation CaptureEngine
    mfcm100.dll                10.0.40219.325              MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.325              MFC Managed Library - Retail Version
    mfcm120.dll                12.0.21005.1                MFC Managed Library - Retail Version
    mfcm120u.dll               12.0.21005.1                MFC Managed Library - Retail Version
    mfcm140.dll                14.36.32532.0               MFC Managed Library - Retail Version
    mfcm140u.dll               14.36.32532.0               MFC Managed Library - Retail Version
    mfcore.dll                 10.0.19041.2965             Media Foundation Core DLL
    mfcsubs.dll                2001.12.10941.16384         COM+
    mfds.dll                   10.0.19041.1645             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                10.0.19041.1                Media Foundation DV Decoder
    mferror.dll                10.0.19041.1                 DLL  Media Foundation
    mfh263enc.dll              10.0.19041.1                Media Foundation h263 Encoder
    mfh264enc.dll              10.0.19041.1806             Media Foundation H264 Encoder
    mfksproxy.dll              10.0.19041.1                Dshow MF Bridge DLL DLL
    mfmediaengine.dll          10.0.19041.1865             Media Foundation Media Engine DLL
    mfmjpegdec.dll             10.0.19041.1348             Media Foundation MJPEG Decoder
    mfmkvsrcsnk.dll            10.0.19041.1566             Media Foundation MKV Media Source and Sink DLL 
    mfmp4srcsnk.dll            10.0.19041.1586              DLL    MPEG4 Media Foundation
    mfmpeg2srcsnk.dll          10.0.19041.2788             Media Foundation MPEG2 Source and Sink DLL
    mfnetcore.dll              10.0.19041.1865             Media Foundation Net Core DLL
    mfnetsrc.dll               10.0.19041.1566             Media Foundation Net Source DLL
    mfperfhelper.dll           10.0.19041.1                MFPerf DLL
    mfplat.dll                 10.0.19041.1865              DLL  Media Foundation
    mfplay.dll                 10.0.19041.746              Media Foundation Playback API DLL
    mfps.dll                   10.0.19041.1949             Media Foundation Proxy DLL
    mfreadwrite.dll            10.0.19041.746              Media Foundation ReadWrite DLL
    mfsensorgroup.dll          10.0.19041.2673             Media Foundation Sensor Group DLL
    mfsrcsnk.dll               10.0.19041.906              Media Foundation Source and Sink DLL
    mfsvr.dll                  10.0.19041.2913             Media Foundation Simple Video Renderer DLL
    mftranscode.dll            10.0.19041.1                Media Foundation Transcode DLL
    mfvdsp.dll                 10.0.19041.746              Windows Media Foundation Video DSP Components
    mfvfw.dll                  10.0.19041.1                MF VFW MFT
    mfwmaaec.dll               10.0.19041.1                Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                10.0.19041.1                Microsoft SNMP Manager API (uses WinSNMP)
    mi.dll                     10.0.19041.546              Management Infrastructure
    mibincodec.dll             10.0.19041.1                Management Infrastructure binary codec component
    microsoft.bluetooth.proxy.dll  10.0.19041.746              Microsoft Bluetooth COM Proxy DLL
    microsoft.management.infrastructure.native.unmanaged.dll  10.0.19041.546              Microsoft.Management.Infrastructure.Native.Unmanaged.dll
    microsoft.uev.appagent.dll  10.0.19041.2913              DLL Microsoft.Uev.AppAgent
    microsoft.uev.office2010customactions.dll  10.0.19041.1620             Microsoft.Uev.Office2010CustomActions DLL
    microsoft.uev.office2013customactions.dll  10.0.19041.2364             Microsoft.Uev.Office2013CustomActions DLL
    microsoftaccounttokenprovider.dll  10.0.19041.746              Microsoft Account Token Provider
    microsoftaccountwamextension.dll  10.0.19041.2913             Microsoft Account WAM Extension DLL
    midimap.dll                10.0.19041.488              Microsoft MIDI Mapper
    migisol.dll                10.0.19041.572              Migration System Isolation Layer
    miguiresource.dll          10.0.19041.1                 MIG wini32
    mimefilt.dll               2008.0.19041.1               MIME
    mimofcodec.dll             10.0.19041.1                 MOF-  
    minstoreevents.dll         10.0.19041.1                Minstore Event Resource
    miracastreceiver.dll       10.0.19041.2673             API  Miracast
    miracastreceiverext.dll    10.0.19041.1806             Miracast Receiver Extensions
    mirrordrvcompat.dll        10.0.19041.1                Mirror Driver Compatibility Helper
    mispace.dll                10.0.19041.2913             Storage Management Provider for Spaces
    mitigationconfiguration.dll  10.0.19041.1566               Exploit Guard
    miutils.dll                10.0.19041.546               
    mixedrealityruntime.dll    10.0.19041.746              MixedRealityRuntime DLL
    mlang.dll                  10.0.19041.746               DLL  
    mmcbase.dll                10.0.19041.1889               DLL MMC
    mmcndmgr.dll               10.0.19041.1566                MMC
    mmcshext.dll               10.0.19041.1889             MMC Shell Extension DLL
    mmdevapi.dll               10.0.19041.2075             MMDevice API
    mmgaclient.dll             10.0.19041.746              MMGA
    mmgaproxystub.dll          10.0.19041.1                MMGA
    mmres.dll                  10.0.19041.1                 
    mobilenetworking.dll       10.0.19041.546              "MobileNetworking.DYNLINK"
    modemui.dll                10.0.19041.1                  Windows
    moricons.dll               10.0.19041.1                Windows NT Setup Icon Resources Library
    moshostclient.dll          10.0.19041.746              MosHostClient
    mosstorage.dll             10.0.19041.1                MosStorage
    mp3dmod.dll                10.0.19041.1                Microsoft MP3 Decoder DMO
    mp43decd.dll               10.0.19041.1165             Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               10.0.19041.1706             Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               10.0.19041.1165             Windows Media MPEG-4 Video Decoder
    mpr.dll                    10.0.19041.1806                  
    mprapi.dll                 10.0.19041.1741             Windows NT MP Router Administration DLL
    mprddm.dll                 10.0.19041.1865                 
    mprdim.dll                 10.0.19041.1566               
    mprext.dll                 10.0.19041.1                 DLL     
    mprmsg.dll                 10.0.19041.1266              (DLL)    
    mrmcorer.dll               10.0.19041.1566             Microsoft Windows MRM
    mrmdeploy.dll              10.0.19041.1                Microsoft Windows MRM Deployment
    mrmindexer.dll             10.0.19041.746              Microsoft Windows MRM
    mrt_map.dll                1.6.24911.0                 Microsoft .NET Native Error Reporting Helper
    mrt100.dll                 1.6.24911.0                 Microsoft .NET Native Runtime
    ms3dthumbnailprovider.dll  10.0.19041.746              3D Builder
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               10.0.19041.1                Microsoft AC-3 Encoder
    msacm32.dll                10.0.19041.1                   Microsoft
    msadce.dll                 10.0.19041.746              OLE DB Cursor Engine
    msadcer.dll                10.0.19041.1                OLE DB Cursor Engine Resources
    msadco.dll                 10.0.19041.746              Remote Data Services Data Control
    msadcor.dll                10.0.19041.1                Remote Data Services Data Control Resources
    msadds.dll                 10.0.19041.746              OLE DB Data Shape Provider
    msaddsr.dll                10.0.19041.1                 OLE DB Data Shape Provider Resources
    msader15.dll               10.0.19041.1                ActiveX Data Objects Resources
    msado15.dll                10.0.19041.746              ActiveX Data Objects
    msadomd.dll                10.0.19041.746              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               10.0.19041.1                Microsoft ActiveX Data Objects Recordset
    msadox.dll                 10.0.19041.746              ActiveX Data Objects Extensions
    msadrh15.dll               10.0.19041.1                ActiveX Data Objects Rowset Helper
    msafd.dll                  10.0.19041.1                Microsoft Windows Sockets 2.0 Service Provider
    msajapi.dll                10.0.19041.1                AllJoyn API Library
    msalacdecoder.dll          10.0.19041.746              Media Foundation ALAC Decoder
    msalacencoder.dll          10.0.19041.746              Media Foundation ALAC Encoder
    msamrnbdecoder.dll         10.0.19041.1                AMR Narrowband Decoder DLL
    msamrnbencoder.dll         10.0.19041.1                AMR Narrowband Encoder DLL
    msamrnbsink.dll            10.0.19041.1                AMR Narrowband Sink DLL
    msamrnbsource.dll          10.0.19041.1                AMR Narrowband Source DLL
    msasn1.dll                 10.0.19041.2251             ASN.1 Runtime APIs
    msauddecmft.dll            10.0.19041.388              Media Foundation Audio Decoders
    msaudite.dll               10.0.19041.2788                
    msauserext.dll             10.0.19041.423              MSA USER Extension DLL
    mscandui.dll               10.0.19041.1                  MSCANDUI
    mscat32.dll                10.0.19041.1                MSCAT32 Forwarder DLL
    msclmd.dll                 10.0.19041.2075             Microsoft Class Mini-driver
    mscms.dll                  10.0.19041.746              DLL-    
    mscoree.dll                10.0.19041.1                Microsoft .NET Runtime Execution Engine
    mscorier.dll               10.0.19041.1                Microsoft .NET Runtime IE resources
    mscories.dll               2.0.50727.9149              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               10.0.19041.1                ODBC Code Page Translator Resources
    mscpxl32.dll               10.0.19041.1                   ODBC
    msctf.dll                  10.0.19041.2673               MSCTF
    msctfmonitor.dll           10.0.19041.546              MsCtfMonitor DLL
    msctfp.dll                 10.0.19041.546              MSCTFP Server DLL
    msctfui.dll                10.0.19041.1                  MSCTFUI
    msctfuimanager.dll         10.0.19041.746              Microsoft UIManager DLL
    msdadc.dll                 10.0.19041.1                OLE DB Data Conversion Stub
    msdadiag.dll               10.0.19041.1                Built-In Diagnostics
    msdaenum.dll               10.0.19041.1                OLE DB Root Enumerator Stub
    msdaer.dll                 10.0.19041.1                OLE DB Error Collection Stub
    msdaora.dll                10.0.19041.746              OLE DB Provider for Oracle
    msdaorar.dll               10.0.19041.1                OLE DB Provider for Oracle Resources
    msdaosp.dll                10.0.19041.1                OLE DB Simple Provider
    msdaprsr.dll               10.0.19041.1                  OLE DB Persistence Services
    msdaprst.dll               10.0.19041.746              OLE DB Persistence Services
    msdaps.dll                 10.0.19041.844              OLE DB Interface Proxies/Stubs
    msdarem.dll                10.0.19041.746              OLE DB Remote Provider
    msdaremr.dll               10.0.19041.1                OLE DB Remote Provider Resources
    msdart.dll                 10.0.19041.1                OLE DB Runtime Routines
    msdasc.dll                 10.0.19041.1                OLE DB Service Components Stub
    msdasql.dll                10.0.19041.1                OLE DB Provider for ODBC Drivers
    msdasqlr.dll               10.0.19041.1                OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                10.0.19041.1                OLE DB Implementation Support Routines
    msdatt.dll                 10.0.19041.1                OLE DB Temporary Table Services
    msdaurl.dll                10.0.19041.1                OLE DB RootBinder Stub
    msdelta.dll                5.0.1.1                     Microsoft Patch Engine
    msdfmap.dll                10.0.19041.746              Data Factory Handler
    msdmo.dll                  10.0.19041.1                DMO Runtime
    msdrm.dll                  10.0.19041.1                   Windows
    msdtcprx.dll               2001.12.10941.16384         Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcspoffln.dll           2001.12.10941.16384         Microsoft Distributed Transaction Coordinator SysPrep Specialize Offline DLL
    msdtcuiu.dll               2001.12.10941.16384         Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.10941.16384             ()  Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9801.21                 Microsoft Jet Excel Isam
    msfeeds.dll                11.0.19041.2546             Microsoft Feeds Manager
    msfeedsbs.dll              11.0.19041.1                  - ()
    msflacdecoder.dll          10.0.19041.1566             Media Foundation FLAC Decoder
    msflacencoder.dll          10.0.19041.746              Media Foundation FLAC Encoder
    msftedit.dll               10.0.19041.1288               "   ",  8.5
    msheif.dll                 10.0.19041.1023             HEIF DLL
    mshtml.dll                 11.0.19041.2965               HTML Microsoft
    mshtmldac.dll              11.0.19041.1                DAC for Trident DOM
    mshtmled.dll               11.0.19041.746              Microsoft HTML Editing Component
    mshtmler.dll               11.0.19041.1                    HTML (Microsoft)
    msi.dll                    5.0.19041.2251              Windows Installer
    msidcrl40.dll              10.0.19041.423              Microsoft Account Dynamic Link Library
    msident.dll                10.0.19041.1                  (Microsoft)
    msidle.dll                 10.0.19041.1                User Idle Monitor
    msidntld.dll               10.0.19041.1                  (Microsoft)
    msieftp.dll                10.0.19041.1320               Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.19041.1                 Windows installer
    msiltcfg.dll               5.0.19041.1                 Windows Installer Configuration API Stub
    msimg32.dll                10.0.19041.1466             GDIEXT Client DLL
    msimsg.dll                 5.0.19041.2251                 Windows
    msimtf.dll                 10.0.19041.1                Active IMM Server DLL
    msisip.dll                 5.0.19041.1566              MSI Signature SIP Provider
    msiso.dll                  11.0.19041.2965             Isolation Library for Internet Explorer
    msiwer.dll                 5.0.19041.1                 MSI Windows Error Reporting
    msjet40.dll                4.0.9801.32                 Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9801.0                  
    msjint40.dll               4.0.9801.1                       Microsoft Jet
    msjro.dll                  10.0.19041.746              Jet and Replication Objects
    msjter40.dll               4.0.9801.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9801.0                  Microsoft Jet Expression Service
    mskeyprotcli.dll           10.0.19041.423                  Windows
    mskeyprotect.dll           10.0.19041.2788                ()
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9801.21                 Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            10.0.19041.1                Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             10.0.19041.1741              Microsoft MPEG-2
    msmpeg2vdec.dll            10.0.19041.2965             Microsoft DTV-DVD Video Decoder
    msobjs.dll                 10.0.19041.2788                
    msoert2.dll                10.0.19041.928              Microsoft Windows Mail RT Lib
    msopusdecoder.dll          10.0.19041.746              Media Foundation Opus Decoder
    msorc32r.dll               10.0.19041.1                  ODBC  Oracle
    msorcl32.dll               10.0.19041.1                ODBC Driver for Oracle
    mspatcha.dll               5.0.1.1                     Microsoft File Patch Application API
    mspatchc.dll               5.0.1.1                     Microsoft Patch Creation Engine
    mspbde40.dll               4.0.9801.15                 Microsoft Jet Paradox Isam
    msphotography.dll          10.0.19041.1023             MS Photography DLL
    msports.dll                10.0.19041.1                   
    msrating.dll               10.0.19041.1                "msrating.DYNLINK"
    msrawimage.dll             10.0.19041.746              MS RAW Image Decoder DLL
    msrd2x40.dll               4.0.9801.18                 Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9801.27                 Microsoft (R) Red ISAM
    msrdc.dll                  10.0.19041.746              Remote Differential Compression COM server
    msrdpwebaccess.dll         10.0.19041.746              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9801.0                  Microsoft Replication Library
    msrle32.dll                10.0.19041.1                Microsoft RLE Compressor
    msscntrs.dll               7.0.19041.2673              PKM Perfmon Counter DLL
    mssign32.dll               10.0.19041.1                 API  
    mssip32.dll                10.0.19041.1                MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.19041.2673              mssitlb
    msspellcheckingfacility.dll  10.0.19041.746                 ()
    mssph.dll                  7.0.19041.2673                 Microsoft
    mssprxy.dll                7.0.19041.2673              Microsoft Search Proxy
    mssrch.dll                 7.0.19041.2673                ()
    mssvp.dll                  7.0.19041.2673               Vista MSSearch
    mstask.dll                 10.0.19041.1                   
    mstext40.dll               4.0.9801.28                 Microsoft Jet Text Isam
    mstscax.dll                10.0.19041.2913             ActiveX-    
    msutb.dll                  10.0.19041.546               (DLL)  MSUTB
    msv1_0.dll                 10.0.19041.2965             Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.48                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.19041.1                 Windows NT IOStreams DLL
    msvcp_win.dll              10.0.19041.789              Microsoft C Runtime Library
    msvcp100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcp110_win.dll           10.0.19041.546              Microsoft STL110 C++ Runtime Library
    msvcp120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcp120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcp140.dll               14.36.32532.0               Microsoft C Runtime Library
    msvcp140_1.dll             14.36.32532.0               Microsoft C Runtime Library _1
    msvcp140_2.dll             14.36.32532.0               Microsoft C Runtime Library _2
    msvcp140_atomic_wait.dll   14.36.32532.0               Microsoft C Runtime Library _atomic_wait
    msvcp140_clr0400.dll       14.10.25028.0               Microsoft C Runtime Library
    msvcp140_codecvt_ids.dll   14.36.32532.0               Microsoft C Runtime Library _codecvt_ids
    msvcp60.dll                7.0.19041.1                 Windows NT C++ Runtime Library DLL
    msvcr100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcr100_clr0400.dll       14.8.4084.0                 Microsoft .NET Framework
    msvcr120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcr120_clr0400.dll       12.0.52519.0                Microsoft C Runtime Library
    msvcrt.dll                 7.0.19041.546               Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               10.0.19041.1                VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                10.0.19041.1                 Microsoft Video  Windows
    msvidc32.dll               10.0.19041.1                  Microsoft Video 1
    msvidctl.dll               6.5.19041.746                ActiveX  
    msvideodsp.dll             10.0.19041.746              Video Stabilization MFT
    msvp9dec.dll               10.0.19041.746              Windows VP9 Video Decoder
    msvproc.dll                10.0.19041.1949             Media Foundation Video Processor
    msvpxenc.dll               10.0.19041.746              Windows VPX Video Encoder
    mswb7.dll                  10.0.19041.546              MSWB7 DLL
    mswdat10.dll               4.0.9801.0                  Microsoft Jet Sort Tables
    mswebp.dll                 10.0.19041.746              WEBP DLL
    mswmdm.dll                 12.0.19041.746                Windows Media Device Manager
    mswsock.dll                10.0.19041.546                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9801.1                    Microsoft Jet
    msxactps.dll               10.0.19041.1                OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9801.25                 Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.19041.844             MSXML 3.0
    msxml3r.dll                8.110.19041.844             XML Resources
    msxml6.dll                 6.30.19041.1081             MSXML 6.0
    msxml6r.dll                6.30.19041.906              XML Resources
    msyuv.dll                  10.0.19041.1                Microsoft UYVY Video Decompressor
    mtf.dll                    10.0.19041.1                "MTF.DYNLINK"
    mtxclu.dll                 2001.12.10941.16384         Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.10941.16384         COM+
    mtxex.dll                  2001.12.10941.16384         COM+
    mtxlegih.dll               2001.12.10941.16384         COM+
    mtxoci.dll                 2001.12.10941.16384         Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           10.0.19041.1                MUI Callback for font registry settings
    mycomput.dll               10.0.19041.746               
    mydocs.dll                 10.0.19041.746                 " "
    napcrypt.dll               10.0.19041.1                NAP Cryptographic API helper
    napinsp.dll                10.0.19041.546                    
    naturallanguage6.dll       10.0.19041.1                Natural Language Development Platform 6
    ncaapi.dll                 10.0.19041.1                Microsoft Network Connectivity Assistant API
    ncdprop.dll                10.0.19041.1                   
    nci.dll                    10.0.19041.1                CoInstaller: NET
    ncobjapi.dll               10.0.19041.1320             Microsoft Windows Operating System
    ncrypt.dll                 10.0.19041.2788              Windows NCrypt
    ncryptprov.dll             10.0.19041.2193             Microsoft KSP
    ncryptsslp.dll             10.0.19041.2846             Microsoft SChannel Provider
    nddeapi.dll                10.0.19041.1                Network DDE Share Management APIs
    ndfapi.dll                 10.0.19041.746              API    
    ndfetw.dll                 10.0.19041.746              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         10.0.19041.746              Network Diagnostic Framework HC Discovery API
    ndishc.dll                 10.0.19041.746                NDIS
    ndproxystub.dll            10.0.19041.1                Network Diagnostic Engine Proxy/Stub
    negoexts.dll               10.0.19041.2006             NegoExtender Security Package
    netapi32.dll               10.0.19041.2130             Net Win32 API DLL
    netbios.dll                10.0.19041.1                NetBIOS Interface Library
    netcenter.dll              10.0.19041.423                 -  
    netcfgx.dll                10.0.19041.746                
    netcorehc.dll              10.0.19041.746                   
    netdiagfx.dll              10.0.19041.746                
    netdriverinstall.dll       10.0.19041.546              Network Driver Installation
    netevent.dll               10.0.19041.1                  
    netfxperf.dll              10.0.19041.1                Extensible Performance Counter Shim
    neth.dll                   10.0.19041.1                   
    netid.dll                  10.0.19041.2130                 
    netiohlp.dll               10.0.19041.2193              DLL   Netio
    netjoin.dll                10.0.19041.2913              DLL   
    netlogon.dll               10.0.19041.2913                Net Logon
    netmsg.dll                 10.0.19041.2251               
    netplwiz.dll               10.0.19041.2913                  
    netprofm.dll               10.0.19041.2913             Network List Manager
    netprovfw.dll              10.0.19041.2913             Provisioning Service Framework DLL
    netprovisionsp.dll         10.0.19041.2913             Provisioning Service Provider DLL
    netsetupapi.dll            10.0.19041.546              Network Configuration API
    netsetupengine.dll         10.0.19041.546              Network Configuration Engine
    netsetupshim.dll           10.0.19041.746              Network Configuration API
    netshell.dll               10.0.19041.1266               
    netutils.dll               10.0.19041.1466             Net Win32 API Helpers DLL
    networkcollectionagent.dll  11.0.19041.746              Network Collection Agent
    networkexplorer.dll        10.0.19041.1                 
    networkhelper.dll          10.0.19041.746              Network utilities for mail, contacts, calendar
    networkitemfactory.dll     10.0.19041.1                  
    newdev.dll                 6.0.5054.0                    
    ngccredprov.dll            10.0.19041.2546                 Microsoft Passport
    ngckeyenum.dll             10.0.19041.2075                 Microsoft Passport
    ngcksp.dll                 10.0.19041.1                Microsoft Passport Key Storage Provider
    ngclocal.dll               10.0.19041.1202             NGC Local Account APIs
    ninput.dll                 10.0.19041.546              Microsoft Pen and Touch Input Component
    nlaapi.dll                 10.0.19041.546              Network Location Awareness 2
    nlhtml.dll                 2008.0.19041.1               HTML
    nlmgp.dll                  10.0.19041.746                 
    nlmproxy.dll               10.0.19041.2913             Network List Manager Public Proxy
    nlmsprep.dll               10.0.19041.2913             Network List Manager Sysprep Module
    nlsbres.dll                10.0.19041.1                 NLSBuild
    nlsdata0000.dll            10.0.19041.1                Microsoft Neutral Natural Language Server Data and Code
    nlsdata0009.dll            10.0.19041.1                Microsoft English Natural Language Server Data and Code
    nlsdl.dll                  10.0.19041.1                Nls Downlevel DLL
    nmadirect.dll              10.0.19041.746              Nma Direct
    normaliz.dll               10.0.19041.546              Unicode Normalization DLL
    npmproxy.dll               10.0.19041.2913             Network List Manager Proxy
    npsm.dll                   10.0.19041.746              NPSM
    npsmdesktopprovider.dll    10.0.19041.746              <d>  DLL     NPSM
    nshhttp.dll                10.0.19041.964               DLL netsh  HTTP
    nshipsec.dll               10.0.19041.964               DLL  IPSec  Net
    nshwfp.dll                 10.0.19041.2913                 Windows  Netsh
    nsi.dll                    10.0.19041.610              NSI User-mode interface DLL
    ntasn1.dll                 10.0.19041.546              Microsoft ASN.1 API
    ntdll.dll                  10.0.19041.2965               NT
    ntdsapi.dll                10.0.19041.2486             Active Directory Domain Services API
    ntlanman.dll               10.0.19041.2604             Microsoft LAN Manager
    ntlanui2.dll               10.0.19041.1                    
    ntlmshared.dll             10.0.19041.2846             NTLM Shared Functionality
    ntmarta.dll                10.0.19041.546               Windows NT MARTA
    ntprint.dll                10.0.19041.1806                 
    ntshrui.dll                10.0.19041.844               ,   
    ntvdm64.dll                10.0.19041.1023             16-   NT64
    nvapi.dll                  31.0.15.3667                NVIDIA NVAPI Library, Version 536.67 
    nvaudcap32v.dll            1.0.3219.3813               NVIDIA Virtual Audio Driver
    nvcuda.dll                 31.0.15.3667                NVIDIA CUDA Driver, Version 536.67 
    nvcuvid.dll                7.17.15.3667                NVIDIA CUDA Video Decode API, Version 536.67 
    nvencodeapi.dll            31.0.15.3667                NVIDIA Video Encoder API, Version 11.0 
    nvfbc.dll                  6.14.15.3667                NVIDIA Frame Buffer Capture Library, Version 
    nvifr.dll                  6.14.15.3667                NVIDIA In-band Frame Rendering Library, Version 
    nvofapi.dll                                            
    nvspcap.dll                3.27.0.112                  NVIDIA Game Proxy
    objsel.dll                 10.0.19041.2075               
    occache.dll                11.0.19041.1                    
    ocsetapi.dll               10.0.19041.1741             Windows Optional Component Setup API
    odbc32.dll                 10.0.19041.1741             ODBC Driver Manager
    odbcbcp.dll                10.0.19041.1                BCP for ODBC
    odbcconf.dll               10.0.19041.388              ODBC Driver Configuration Program
    odbccp32.dll               10.0.19041.1                ODBC Installer
    odbccr32.dll               10.0.19041.1                ODBC Cursor Library
    odbccu32.dll               10.0.19041.1                ODBC Cursor Library
    odbcint.dll                10.0.19041.1                ODBC Resources
    odbcji32.dll               10.0.19041.1                Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               10.0.19041.1                Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               10.0.19041.1                ODBC Driver Manager Trace
    oddbse32.dll               10.0.19041.1                ODBC (3.0) driver for DBase
    odexl32.dll                10.0.19041.1                ODBC (3.0) driver for Excel
    odfox32.dll                10.0.19041.1                ODBC (3.0) driver for FoxPro
    odpdx32.dll                10.0.19041.1                ODBC (3.0) driver for Paradox
    odtext32.dll               10.0.19041.1                ODBC (3.0) driver for text files
    oemlicense.dll             10.0.19041.546              Client Licensing Platform Client Provisioning
    offfilt.dll                2008.0.19041.1               OFFICE
    offlinelsa.dll             10.0.19041.2913             Windows
    offlinesam.dll             10.0.19041.2788             Windows
    offreg.dll                 10.0.19041.2130             Offline registry DLL
    ole2.dll                   3.10.0.103                  Windows Win16 Application Launcher
    ole2disp.dll               3.10.0.103                  Windows Win16 Application Launcher
    ole2nls.dll                3.10.0.103                  Windows Win16 Application Launcher
    ole32.dll                  10.0.19041.2965             Microsoft OLE  Windows
    oleacc.dll                 7.2.19041.746               Active Accessibility Core Component
    oleacchooks.dll            7.2.19041.546               Active Accessibility Event Hooks Library
    oleaccrc.dll               7.2.19041.1                 Active Accessibility Resource DLL
    oleaut32.dll               10.0.19041.985              OLEAUT32.DLL
    olecli32.dll               10.0.19041.1                  OLE
    oledb32.dll                10.0.19041.746              OLE DB Core Services
    oledb32r.dll               10.0.19041.1                   OLE DB
    oledlg.dll                 10.0.19041.746                 OLE
    oleprn.dll                 10.0.19041.1237             Oleprn DLL
    olepro32.dll               10.0.19041.84               OLEPRO32.DLL
    olesvr32.dll               10.0.19041.1                Object Linking and Embedding Server Library
    olethk32.dll               10.0.19041.1                Microsoft OLE for Windows
    omadmapi.dll               10.0.19041.2788             omadmapi
    ondemandbrokerclient.dll   10.0.19041.746              OnDemandBrokerClient
    ondemandconnroutehelper.dll  10.0.19041.2311             On Demand Connctiond Route Helper
    onecorecommonproxystub.dll  10.0.19041.2546             OneCore Common Proxy Stub
    onecoreuapcommonproxystub.dll  10.0.19041.2311             OneCoreUAP Common Proxy Stub
    onedrivesettingsyncprovider.dll  10.0.19041.1806             OneDrive Setting Sync
    onesettingsclient.dll      10.0.19041.2311              Microsoft OneSettings
    onex.dll                   10.0.19041.928                IEEE 802.1X
    onexui.dll                 10.0.19041.1                   IEEE 802.1X
    onnxruntime.dll            1.0.1911.2111               ONNX Runtime
    opcservices.dll            10.0.19041.2075             Native Code OPC Services Library
    opencl.dll                 3.0.3.0                     OpenCL Client DLL
    opengl32.dll               10.0.19041.2193             OpenGL Client DLL
    ortcengine.dll             2018.6.1.57                 Microsoft Skype ORTC Engine
    osbaseln.dll               10.0.19041.1                Service Reporting API
    osuninst.dll               10.0.19041.1                Uninstall Interface
    p2p.dll                    10.0.19041.1                  
    p2pgraph.dll               10.0.19041.1                Peer-to-Peer Graphing
    p2pnetsh.dll               10.0.19041.1                   NetSh
    packager.dll               10.0.19041.1023              2
    packagestateroaming.dll    10.0.19041.746              Package State Roaming
    panmap.dll                 10.0.19041.1                PANOSE(tm) Font Mapper
    pautoenr.dll               10.0.19041.1                  
    payloadrestrictions.dll    10.0.19041.1949             Payload Restrictions Mitigation Provider
    paymentmediatorserviceproxy.dll  10.0.19041.1                Payment Mediator Service Proxy
    pcacli.dll                 10.0.19041.546              Program Compatibility Assistant Client Module
    pcaui.dll                  10.0.19041.546                  
    pcpksp.dll                 10.0.19041.2546                 ()    
    pcshellcommonproxystub.dll  10.0.19041.2311             PCShell Common Proxy Stub
    pcwum.dll                  10.0.19041.1                     DLL Windows
    pdh.dll                    10.0.19041.1202                 Windows
    pdhui.dll                  10.0.19041.1                  
    peerdist.dll               10.0.19041.546                BranchCache
    peerdistsh.dll             10.0.19041.1151               BranchCache Netshell
    peopleapis.dll             10.0.19041.746              DLL for PeopleRT
    perceptiondevice.dll       10.0.19041.746              Perception Device
    perceptionsimulation.proxystubs.dll  10.0.19041.1                Windows Perception Simulation Proxy Stubs
    perfctrs.dll               10.0.19041.488               
    perfdisk.dll               10.0.19041.488                  Windows
    perfnet.dll                10.0.19041.488                   Windows
    perfos.dll                 10.0.19041.488                  Windows
    perfproc.dll               10.0.19041.488                   Windows
    perfts.dll                 10.0.19041.1566             Windows Remote Desktop Services Performance Objects
    phonecallhistoryapis.dll   10.0.19041.746              DLL for PhoneCallHistoryRT
    phoneom.dll                10.0.19041.2788             Phone Object Model
    phoneplatformabstraction.dll  10.0.19041.746              Phone Platform Abstraction
    phoneutil.dll              10.0.19041.746              Phone utilities
    phoneutilres.dll           10.0.19041.1                   ""
    photometadatahandler.dll   10.0.19041.746              Photo Metadata Handler
    photowiz.dll               10.0.19041.1                  
    pickerplatform.dll         10.0.19041.1806             PickerPlatform
    pid.dll                    10.0.19041.1                Microsoft PID
    pidgenx.dll                10.0.19041.1708             Pid Generation
    pifmgr.dll                 10.0.19041.1                Windows NT PIF Manager Icon Resources Library
    pimindexmaintenanceclient.dll  10.0.19041.746              Client dll for Pim Index Maintenance
    pimstore.dll               10.0.19041.746              POOM
    pku2u.dll                  10.0.19041.1806             Pku2u Security Package
    pla.dll                    10.0.19041.1                   
    playlistfolder.dll         10.0.19041.746              Playlist Folder
    playsndsrv.dll             10.0.19041.746               PlaySound
    playtodevice.dll           10.0.19041.746              DLL-   
    playtomanager.dll          10.0.19041.2546             Microsoft Windows PlayTo Manager
    playtomenu.dll             12.0.19041.746                 "  "
    playtoreceiver.dll         10.0.19041.746              DLNA DMR DLL
    playtostatusprovider.dll   10.0.19041.746               DLL   
    pngfilt.dll                11.0.19041.746              IE PNG plugin image decoder
    pnrpnsp.dll                10.0.19041.546                 PNRP
    policymanager.dll          10.0.19041.2913             Policy Manager DLL
    polstore.dll               10.0.19041.1682             Policy Storage dll
    portabledeviceapi.dll      10.0.19041.746               API    Windows
    portabledeviceclassextension.dll  10.0.19041.746              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  10.0.19041.746              Portable Device Connection API Components
    portabledevicestatus.dll   10.0.19041.746                  Microsoft Windows
    portabledevicesyncprovider.dll  10.0.19041.746                 Microsoft Windows
    portabledevicetypes.dll    10.0.19041.746              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  10.0.19041.1566             PortableDevice WIA Compatibility Driver
    posyncservices.dll         10.0.19041.746              Change Tracking
    pots.dll                   10.0.19041.1                 
    powercpl.dll               10.0.19041.423                
    powrprof.dll               10.0.19041.546              DLL     
    presentationcffrasterizernative_v0300.dll  3.0.6920.9141               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  10.0.19041.1                Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.9141               PresentationNative_v0300.dll
    prflbmsg.dll               10.0.19041.1                    
    print.printsupport.source.dll  10.0.19041.2913             Microsoft Windows Print Support
    print.workflow.source.dll  10.0.19041.2913             Microsoft Windows Print Workflow Source App Library
    printconfig.dll            0.3.19041.2965                PrintConfig
    printplatformconfig.dll    10.0.19041.1806             Legacy Print Platform Adapter
    printrenderapihost.dll     10.0.19041.1806             PDF Writer
    printui.dll                10.0.19041.1806                
    printworkflowservice.dll   10.0.19041.2913                  Microsoft Windows
    printwsdahost.dll          10.0.19041.1806             PrintWSDAHost
    prncache.dll               10.0.19041.1806             Print UI Cache
    prnfldr.dll                10.0.19041.1806             prnfldr dll
    prnntfy.dll                10.0.19041.1806             prnntfy DLL
    prntvpt.dll                10.0.19041.1806             Print Ticket Services Module
    profapi.dll                10.0.19041.844              User Profile Basic API
    profext.dll                10.0.19041.2673             profext
    propsys.dll                7.0.19041.1741                 ()
    provcore.dll               10.0.19041.746                   ()
    provisioningcommandscsp.dll  10.0.19041.2788             Provisioning package command configuration service provider
    provmigrate.dll            10.0.19041.2788             Provisioning Migration Handler
    provplatformdesktop.dll    10.0.19041.2788                   
    provsvc.dll                10.0.19041.1466               Windows
    provthrd.dll               10.0.19041.1                WMI Provider Thread & Log Library
    proximitycommon.dll        10.0.19041.1                   
    proximitycommonpal.dll     10.0.19041.746              Proximity Common PAL
    proximityrtapipal.dll      10.0.19041.1                Proximity WinRT API PAL
    prvdmofcomp.dll            10.0.19041.1                WMI
    psapi.dll                  10.0.19041.546              Process Status Helper
    pshed.dll                  10.0.19041.1                  ,   
    psisdecd.dll               10.0.19041.746              Microsoft SI/PSI parser for MPEG2 based networks.
    psmodulediscoveryprovider.dll  10.0.19041.1                WMI
    pstorec.dll                10.0.19041.1                Deprecated Protected Storage COM interfaces
    puiapi.dll                 10.0.19041.1806              DLL puiapi
    puiobj.dll                 10.0.19041.1806              DLL  PrintUI
    pwrshplugin.dll            10.0.19041.1                pwrshplugin.dll
    qasf.dll                   12.0.19041.1                DirectShow ASF Support
    qcap.dll                   10.0.19041.1                  DirecxX DirectShow.
    qdv.dll                    10.0.19041.1                  DirecxX DirectShow.
    qdvd.dll                   10.0.19041.746              DirectShow DVD PlayBack Runtime.
    qedit.dll                  10.0.19041.746               DirectShow
    qedwipes.dll               10.0.19041.1                DirectShow Editing SMPTE Wipes
    quartz.dll                 10.0.19041.746                DirecxX DirectShow.
    query.dll                  10.0.19041.1                    
    qwave.dll                  10.0.19041.1741             Windows NT
    racengn.dll                10.0.19041.1                    
    racpldlg.dll               10.0.19041.1110                
    radardt.dll                10.0.19041.1                     Windows
    radarrs.dll                10.0.19041.1                     Microsoft Windows
    radcui.dll                 10.0.19041.746                      RemoteApp
    rasadhlp.dll               10.0.19041.546              Remote Access AutoDial Helper
    rasapi32.dll               10.0.19041.1865             API  
    raschap.dll                10.0.19041.2604                PPP CHAP
    raschapext.dll             10.0.19041.746                Windows  RasChap
    rasctrs.dll                10.0.19041.1                       Windows NT
    rasdiag.dll                10.0.19041.746                  RAS
    rasdlg.dll                 10.0.19041.867              API     
    rasgcw.dll                 10.0.19041.867                RAS
    rasman.dll                 10.0.19041.1949             Remote Access Connection Manager
    rasmontr.dll               10.0.19041.1266               RAS
    rasplap.dll                10.0.19041.867                 RAS PLAP
    rasppp.dll                 10.0.19041.2486             Remote Access PPP
    rastapi.dll                10.0.19041.1110             Remote Access TAPI Compliance Layer
    rastls.dll                 10.0.19041.2913                PPP EAP-TLS
    rastlsext.dll              10.0.19041.2913               Windows  RasTls
    rdpbase.dll                10.0.19041.2075             Rdp OneCore Base Services
    rdpcore.dll                10.0.19041.2913             RDP Core DLL
    rdpencom.dll               10.0.19041.746              RDPSRAPI COM Objects
    rdpendp.dll                10.0.19041.746                 RDP
    rdpsaps.dll                10.0.19041.1                RDP Session Agent Proxy Stub
    rdpserverbase.dll          10.0.19041.2075             Rdp Server OneCore Base Services
    rdpsharercom.dll           10.0.19041.2075             RDPSRAPI Sharer COM Objects
    rdpviewerax.dll            10.0.19041.746              RDPSRAPI Viewer COM Objects and ActiveX
    rdvgocl32.dll              10.0.19041.488              Microsoft RemoteFX OpenCL ICD
    rdvgogl32.dll              10.0.19041.488              Microsoft RemoteFX OpenGL
    rdvgu1132.dll              10.0.19041.928              Microsoft RemoteFX Virtual GPU
    rdvgumd32.dll              10.0.19041.928              Microsoft RemoteFX Virtual GPU
    rdvvmtransport.dll         10.0.19041.964              RdvVmTransport EndPoints
    reagent.dll                10.0.19041.964               DLL   Microsoft Windows
    regapi.dll                 10.0.19041.1865             Registry Configuration APIs
    regctrl.dll                10.0.19041.746              RegCtrl
    reguwpapi.dll              10.0.19041.1                UWP Registry API
    reinfo.dll                 10.0.19041.1                Microsoft Windows Recovery Info DLL
    remoteaudioendpoint.dll    10.0.19041.1503             Remote Audio Endpoint
    remotepg.dll               10.0.19041.964              CPL-  
    removedevicecontexthandler.dll  10.0.19041.746                    
    removedeviceelevated.dll   10.0.19041.1                RemoveDeviceElevated Proxy Dll
    resampledmo.dll            10.0.19041.1                Windows Media Resampler
    resourcepolicyclient.dll   10.0.19041.546              Resource Policy Client
    resutils.dll               10.0.19041.1949              DLL     ()
    rgb9rast.dll               10.0.19041.1                Microsoft Windows Operating System
    riched20.dll               5.31.23.1231                Rich Text Edit Control, v3.1
    riched32.dll               10.0.19041.1                Wrapper Dll for Richedit 1.0
    rmclient.dll               10.0.19041.746              Resource Manager Client
    rnr20.dll                  10.0.19041.1                Windows Socket2 NameSpace DLL
    rometadata.dll             4.8.3673.0                  Microsoft MetaData Library
    rpchttp.dll                10.0.19041.2728             RPC HTTP DLL
    rpcns4.dll                 10.0.19041.1                      (RPC)
    rpcnsh.dll                 10.0.19041.1                  RPC Netshell
    rpcrt4.dll                 10.0.19041.2965                
    rpcrtremote.dll            10.0.19041.2728             Remote RPC Extension
    rsaenh.dll                 10.0.19041.1052             Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 10.0.19041.1                  
    rstrtmgr.dll               10.0.19041.1                 
    rtffilt.dll                2008.0.19041.1               RTF
    rtm.dll                    10.0.19041.1320               
    rtmcodecs.dll              2018.6.1.57                 Microsoft Real Time Media Codec Library
    rtmediaframe.dll           10.0.19041.746              Windows Runtime MediaFrame DLL
    rtmmvrortc.dll             2018.6.1.57                 Microsoft Real Time Media ORTC Video Renderer
    rtmpal.dll                 2018.6.1.57                 Microsoft Real Time Media Stack PAL
    rtmpltfm.dll               2018.6.1.57                 Microsoft Real Time Media Stack
    rtutils.dll                10.0.19041.2846             Routing Utilities
    rtvcvfw32.dll                                          
    rtworkq.dll                10.0.19041.1741             Realtime WorkQueue DLL
    samcli.dll                 10.0.19041.1466             Security Accounts Manager Client DLL
    samlib.dll                 10.0.19041.2788             SAM Library DLL
    sas.dll                    10.0.19041.1                WinLogon Software SAS Library
    sbe.dll                    10.0.19041.1                DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.19041.1                Stream Buffer IO DLL
    sberes.dll                 10.0.19041.1                    DirectShow.
    scansetting.dll            10.0.19041.1806                   Microsoft Windows(TM)
    scarddlg.dll               10.0.19041.1                SCardDlg -   -
    scecli.dll                 10.0.19041.2913                 Windows
    scesrv.dll                 10.0.19041.2913                Windows
    schannel.dll               10.0.19041.2913               TLS/SSL
    schedcli.dll               10.0.19041.1466             Scheduler Service Client DLL
    scksp.dll                  10.0.19041.1                Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.19041.746               Microsoft ScriptO
    scrobj.dll                 5.812.10240.16384           Windows  Script Component Runtime
    scrptadm.dll               10.0.19041.572                
    scrrun.dll                 5.812.10240.16384           Microsoft  Script Runtime
    sdiageng.dll               10.0.19041.2546                
    sdiagprv.dll               10.0.19041.1                API    Windows
    sdohlp.dll                 10.0.19041.746                 SDO NPS
    search.protocolhandler.mapi2.dll  7.0.19041.2673                 ()  MAPI2
    searchfolder.dll           10.0.19041.1620             SearchFolder
    sechost.dll                10.0.19041.2913             Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                10.0.19041.2006             Windows Rights Management Desktop Security Processor
    secproc_isv.dll            10.0.19041.1682             Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            10.0.19041.1682             Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        10.0.19041.1                Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                10.0.19041.546              Security Support Provider Interface
    security.dll               10.0.19041.1                Security Support Provider Interface
    securitycenterbrokerps.dll  10.0.19041.329              SecurityCenterBrokerPS
    semgrps.dll                10.0.19041.1                SEMgrSvc Proxy
    sendmail.dll               10.0.19041.746               
    sensapi.dll                10.0.19041.1                SENS Connectivity API DLL
    sensorsapi.dll             10.0.19041.746              API 
    sensorscpl.dll             10.0.19041.1                  "    "
    sensorsnativeapi.dll       10.0.19041.2311             Sensors Native API
    sensorsnativeapi.v2.dll    10.0.19041.2311             Sensors Native API (V2 stack)
    sensorsutilsv2.dll         10.0.19041.746               DLL      2
    serialui.dll               10.0.19041.1                  
    serwvdrv.dll               10.0.19041.1                  Unimodem
    sessenv.dll                10.0.19041.2075                  
    settingmonitor.dll         10.0.19041.1806             Setting Synchronization Change Monitor
    settingsync.dll            10.0.19041.2913             Setting Synchronization
    settingsynccore.dll        10.0.19041.2193             Setting Synchronization Core
    setupapi.dll               10.0.19041.2193             Windows Setup API
    setupcl.dll                10.0.19041.2788                
    setupcln.dll               10.0.19041.2546               
    sfc.dll                    10.0.19041.2075             Windows File Protection
    sfc_os.dll                 10.0.19041.2311             Windows File Protection
    shacct.dll                 10.0.19041.610              Shell Accounts Classes
    shacctprofile.dll          10.0.19041.1466             Shell Accounts Profile Classes
    sharehost.dll              10.0.19041.2311             ShareHost
    shcore.dll                 10.0.19041.1645             SHCORE
    shdocvw.dll                10.0.19041.2728                   
    shell32.dll                10.0.19041.2788                Windows
    shellcommoncommonproxystub.dll  10.0.19041.2913             ShellCommon Common Proxy Stub
    shellstyle.dll             10.0.19041.1                Windows Shell Style Resource Dll
    shfolder.dll               10.0.19041.1                Shell Folder Service
    shgina.dll                 10.0.19041.1                Windows Shell User Logon
    shimeng.dll                10.0.19041.2913             Shim Engine DLL
    shimgvw.dll                10.0.19041.1                 
    shlwapi.dll                10.0.19041.2075                
    shpafact.dll               10.0.19041.1                Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                10.0.19041.746              Shell setup helper
    shsvcs.dll                 10.0.19041.1741              DLL   Windows
    shunimpl.dll               10.0.19041.1                Windows Shell Obsolete APIs
    shutdownext.dll            10.0.19041.1                     
    shwebsvc.dll               10.0.19041.746              -  Windows
    signdrv.dll                10.0.19041.1110             WMI provider for Signed Drivers
    simauth.dll                10.0.19041.1                DLL   EAP-SIM
    simcfg.dll                 10.0.19041.1                EAP SIM config dll
    slc.dll                    10.0.19041.1682             Software Licensing Client DLL
    slcext.dll                 10.0.19041.1682             Software Licensing Client Extension Dll
    slwga.dll                  10.0.19041.1                Software Licensing WGA API
    smartcardcredentialprovider.dll  10.0.19041.1202                - Windows
    smartscreenps.dll          10.0.19041.1865             SmartScreenPS
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    smphost.dll                10.0.19041.2913             Storage Management Provider (SMP) host service
    sndvolsso.dll              10.0.19041.1741              SCA 
    snmpapi.dll                10.0.19041.1                SNMP Utility Library
    socialapis.dll             10.0.19041.746              DLL for SocialRT
    softkbd.dll                10.0.19041.1                    
    softpub.dll                10.0.19041.1                Softpub Forwarder DLL
    sortserver2003compat.dll   10.0.19041.1                Sort Version Server 2003
    sortwindows61.dll          10.0.19041.1                SortWindows61 Dll
    sortwindows62.dll          10.0.19041.1682             SortWindows62 Dll
    sortwindows64.dll          10.0.19041.1741             SortWindows64 Dll
    sortwindows6compat.dll     10.0.19041.1                Sort Version Windows 6.0
    spacebridge.dll            10.0.19041.1806             SpaceBridge
    spatializerapo.dll         10.0.19041.1266             Spatializer APO
    spbcd.dll                  10.0.19041.1237             BCD Sysprep Plugin
    spfileq.dll                10.0.19041.1320             Windows SPFILEQ
    spinf.dll                  10.0.19041.546              Windows SPINF
    spnet.dll                  10.0.19041.1                Net Sysprep Plugin
    spopk.dll                  10.0.19041.746              OPK Sysprep Plugin
    spp.dll                    10.0.19041.2673                 Microsoft Windows
    sppc.dll                   10.0.19041.1682             Software Licensing Client DLL
    sppcext.dll                10.0.19041.1682             Software Protection Platform Client Extension Dll
    sppcomapi.dll              10.0.19041.1865                
    sppinst.dll                10.0.19041.1                SPP CMI Installer Plug-in DLL
    sppwmi.dll                 10.0.19041.1                Software Protection Platform WMI provider
    spwinsat.dll               10.0.19041.1                WinSAT Sysprep Plugin
    spwizeng.dll               10.0.19041.746              Setup Wizard Framework
    spwmp.dll                  12.0.19041.1266             Windows Media Player System Preparation DLL
    sqloledb.dll               10.0.19041.2846             OLE DB Provider for SQL Server
    sqlsrv32.dll               10.0.19041.2913             SQL Server ODBC Driver
    sqlunirl.dll               2000.80.2039.0              String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 2000.80.2039.0              Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 2000.80.2040.0              Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                10.0.19041.1                XML extensions for SQL Server
    sqmapi.dll                 10.0.19041.1                SQM Client
    srchadmin.dll              7.0.19041.746                
    srclient.dll               10.0.19041.2673             Microsoft Windows System Restore Client Library
    srm.dll                    10.0.19041.1                      Microsoft
    srm_ps.dll                 10.0.19041.1                Microsoft FSRM internal proxy/stub
    srmclient.dll              10.0.19041.1645             Microsoft File Server Resource Management Client Extensions
    srmlib.dll                 10.0.19041.1                Microsoft (R) File Server Resource Management Interop Assembly
    srmscan.dll                10.0.19041.1645             Microsoft File Server Storage Reports Scan Engine
    srmshell.dll               10.0.19041.746                    ()
    srmstormod.dll             10.0.19041.746              Microsoft File Server Resource Management Office Parser
    srmtrace.dll               10.0.19041.1                Microsoft File Server Resource Management Tracing Library
    srpapi.dll                 10.0.19041.2311              DLL   (API)   
    srpuxnativesnapin.dll      10.0.19041.1                       
    srumapi.dll                10.0.19041.746              System Resource Usage Monitor API
    srumsvc.dll                10.0.19041.746              System Resource Usage Monitor Service
    srvcli.dll                 10.0.19041.1645             Server Service Client DLL
    sscore.dll                 10.0.19041.1151              DLL-  
    ssdm.dll                                               
    ssdpapi.dll                10.0.19041.1                SSDP Client API DLL
    sspicli.dll                10.0.19041.2130             Security Support Provider Interface
    ssshim.dll                 10.0.19041.1                Windows Componentization Platform Servicing API
    startupscan.dll            10.0.19041.1                 DLL    
    staterepository.core.dll   10.0.19041.2673             StateRepository Core
    stclient.dll               2001.12.10941.16384         COM+ Configuration Catalog Client
    sti.dll                    10.0.19041.1806                  
    stobject.dll               10.0.19041.1806                Systray
    storage.dll                3.10.0.103                  Windows Win16 Application Launcher
    storagecontexthandler.dll  10.0.19041.746                   
    storagewmi.dll             10.0.19041.964              WMI Provider for Storage Management
    storagewmi_passthru.dll    10.0.19041.1                WMI PassThru Provider for Storage Management
    storprop.dll               10.0.19041.1                    
    structuredquery.dll        7.0.19041.746               Structured Query
    sud.dll                    10.0.19041.746                SUD
    sxproxy.dll                10.0.19041.2673                 Microsoft Windows
    sxs.dll                    10.0.19041.2788             Fusion 2.5
    sxshared.dll               10.0.19041.1                Microsoft Windows SX Shared Library
    sxsstore.dll               10.0.19041.1                Sxs Store DLL
    synccenter.dll             10.0.19041.423                
    synccontroller.dll         10.0.19041.746              SyncController for managing sync of mail, contacts, calendar
    synchostps.dll             10.0.19041.1                Proxystub for sync host
    syncinfrastructure.dll     10.0.19041.746                Microsoft Windows.
    syncinfrastructureps.dll   10.0.19041.1                Microsoft Windows sync infrastructure proxy stub.
    syncproxy.dll              10.0.19041.746              SyncProxy for RPC communication about sync of mail, contacts, calendar
    syncreg.dll                2007.94.19041.1             Microsoft Synchronization Framework Registration
    syncres.dll                10.0.19041.1                 ActiveSync
    syncsettings.dll           10.0.19041.2913              
    syncutil.dll               10.0.19041.746              Sync utilities for mail, contacts, calendar
    syssetup.dll               10.0.19041.1                Windows NT System Setup
    systemcpl.dll              10.0.19041.423              CPL 
    systemeventsbrokerclient.dll  10.0.19041.1202             system Events Broker Client Library
    systemsettings.datamodel.dll  10.0.19041.746              SystemSettings.Datamodel private API
    systemsupportinfo.dll      10.0.19041.746              Microsoft Windows operating system.
    t2embed.dll                10.0.19041.264              Microsoft T2Embed Font Embedding
    tapi3.dll                  10.0.19041.1645             Microsoft TAPI3
    tapi32.dll                 10.0.19041.423               API  Microsoft Windows
    tapimigplugin.dll          10.0.19041.746              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               10.0.19041.1                Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                10.0.19041.450                 Microsoft Windows
    tapisysprep.dll            10.0.19041.1                Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 10.0.19041.1                 DLL   Microsoft Windows
    taskapis.dll               10.0.19041.746              DLL for TaskRT
    taskcomp.dll               10.0.19041.1503                 
    taskschd.dll               10.0.19041.1266             Task Scheduler COM API
    taskschdps.dll             10.0.19041.906              Task Scheduler Interfaces Proxy
    t-base_client_api.dll      4.11.0.0                    t-base_client_api dll
    tbaseregistry32.dll        4.6.1.1                     tbaseregistry dll
    tbauth.dll                 10.0.19041.1503             TBAuth protocol handler
    tbs.dll                    10.0.19041.906              TBS
    tcpipcfg.dll               10.0.19041.746                
    tcpmib.dll                 10.0.19041.1806             Standard TCP/IP Port Monitor Helper DLL
    tcpmonui.dll               10.0.19041.1806                 TCP/IP
    tdh.dll                    10.0.19041.2788                
    tempsignedlicenseexchangetask.dll  10.0.19041.546              TempSignedLicenseExchangeTask Task
    tenantrestrictionsplugin.dll  10.0.19041.1741             Tenant Restrictions Plugin DLL
    termmgr.dll                10.0.19041.746              Microsoft TAPI3 Terminal Manager
    tetheringclient.dll        10.0.19041.1                Tethering Client
    textinputframework.dll     10.0.19041.2913             "TextInputFramework.DYNLINK"
    textinputmethodformatter.dll                              
    textshaping.dll                                        
    themecpl.dll               10.0.19041.1806             CPL 
    themeui.dll                10.0.19041.746              API   Windows
    threadpoolwinrt.dll        10.0.19041.746              Windows WinRT Threadpool
    thumbcache.dll             10.0.19041.1466               
    tiledatarepository.dll     10.0.19041.2673             Tile Data Repository
    timedatemuicallback.dll    10.0.19041.1                Time Date Control UI Language Change plugin
    tlscsp.dll                 10.0.19041.1                Microsoft Remote Desktop Services Cryptographic Utility
    tokenbinding.dll           10.0.19041.546              Token Binding Protocol
    tokenbroker.dll            10.0.19041.1806              
    tokenbrokerui.dll          10.0.19041.1503             Token Broker UI
    tpmcertresources.dll       10.0.19041.2965             TpmCertResources
    tpmcompc.dll               10.0.19041.1                  
    tpmcoreprovisioning.dll    10.0.19041.2965                  TPM
    tquery.dll                 7.0.19041.2673               Microsoft Tripoli
    traffic.dll                10.0.19041.1                Microsoft Traffic Control 1.0 DLL
    trustedsignalcredprov.dll  10.0.19041.746                 TrustedSignal
    tsbyuv.dll                 10.0.19041.1                Toshiba Video Codec
    tsgqec.dll                 10.0.19041.2913                     
    tsmf.dll                   10.0.19041.746                MF    
    tspkg.dll                  10.0.19041.1766             Web Service Security Package
    tsworkspace.dll            10.0.19041.2311                     RemoteApp
    ttdloader.dll              10.0.19041.1                Time Travel Debugging Runtime Loader
    ttdplm.dll                 10.0.19041.1                Time Travel Debugger PLM APIs
    ttdrecord.dll              10.0.19041.1741             Time Travel Debugging Recording Manager
    ttdrecordcpu.dll           10.0.19041.1                Time Travel Debugging CPU Recorder Runtime
    ttlsauth.dll               10.0.19041.2075             DLL   EAP-TTLS
    ttlscfg.dll                10.0.19041.1                DLL  EAP-TTLS
    ttlsext.dll                10.0.19041.746                Windows  EAP TTLS
    tvratings.dll              10.0.19041.746              Module for managing TV ratings
    twext.dll                  10.0.19041.1766             :  
    twinapi.appcore.dll        10.0.19041.1865             twinapi.appcore
    twinapi.dll                10.0.19041.1741             twinapi
    twinui.appcore.dll         10.0.19041.1949             TWINUI.APPCORE
    twinui.dll                 10.0.19041.2913             TWINUI
    txflog.dll                 2001.12.10941.16384         COM+
    txfw32.dll                 10.0.19041.1                TxF Win32 DLL
    typelib.dll                3.10.0.103                  Windows Win16 Application Launcher
    tzautoupdate.dll           10.0.19041.2788                
    tzres.dll                  10.0.19041.2913              DLL   
    ucmhc.dll                  10.0.19041.746                 UCM
    ucrtbase.dll               10.0.19041.789              Microsoft C Runtime Library
    ucrtbase_clr0400.dll       14.10.25028.0               Microsoft C Runtime Library
    udhisapi.dll               10.0.19041.867              UPnP Device Host ISAPI Extension
    uexfat.dll                 10.0.19041.1023             eXfat Utility DLL
    ufat.dll                   10.0.19041.1023             FAT Utility DLL
    uiamanager.dll             10.0.19041.746              UiaManager
    uianimation.dll            10.0.19041.746              Windows Animation Manager
    uiautomationcore.dll       7.2.19041.2788                 Microsoft UI
    uicom.dll                  10.0.19041.746              Add/Remove Modems
    uimanagerbrokerps.dll      10.0.19041.1                Microsoft UIManager Broker Proxy Stub
    uireng.dll                 10.0.19041.1                    
    uiribbon.dll               10.0.19041.1                  Windows
    ulib.dll                   10.0.19041.1266             DLL   
    umdmxfrm.dll               10.0.19041.1                Unimodem Tranform Module
    umpdc.dll                                              
    unenrollhook.dll           10.0.19041.2788             unenrollhook DLL
    unimdmat.dll               10.0.19041.1                - AT   Unimodem
    uniplat.dll                10.0.19041.1                Unimodem AT Mini Driver Platform Driver for Windows NT
    unistore.dll               10.0.19041.746               
    untfs.dll                  10.0.19041.1266             NTFS Utility DLL
    updatepolicy.dll           10.0.19041.2913                
    upnp.dll                   10.0.19041.2788             API   UPnP
    upnphost.dll               10.0.19041.867                PNP-
    urefs.dll                  10.0.19041.2913             NTFS Utility DLL
    urefsv1.dll                10.0.19041.1                NTFS Utility DLL
    ureg.dll                   10.0.19041.1806             Registry Utility DLL
    url.dll                    11.0.19041.1                Internet Shortcut Shell Extension DLL
    urlmon.dll                 11.0.19041.2788              OLE32  Win32
    usbceip.dll                10.0.19041.1                 USBCEIP
    usbperf.dll                10.0.19041.1                 DLL   USB
    usbui.dll                  10.0.19041.1                USB UI Dll
    user32.dll                 10.0.19041.2965                USER API Windows
    useraccountcontrolsettings.dll  10.0.19041.423                  
    useractivitybroker.dll     10.0.19041.746              useractivitybroker
    usercpl.dll                10.0.19041.2913               
    userdataaccessres.dll      10.0.19041.1                    UserDataAccess
    userdataaccountapis.dll    10.0.19041.746              DLL for UserDataAccountsRT
    userdatalanguageutil.dll   10.0.19041.1                Language-related helper functions for user data
    userdataplatformhelperutil.dll  10.0.19041.746              Platform Utilities for data access
    userdatatimeutil.dll       10.0.19041.2673             Time-related helper functions for user data
    userdatatypehelperutil.dll  10.0.19041.1                Type Utilities for data access
    userdeviceregistration.dll  10.0.19041.2075             AAD User Device Registration WinRT
    userdeviceregistration.ngc.dll  10.0.19041.2193             WinRT    AD/AAD
    userenv.dll                10.0.19041.572              Userenv
    userinitext.dll            10.0.19041.2913              DLL    UserInit
    userlanguageprofilecallback.dll  10.0.19041.1806             MUI Callback for User Language profile changed
    usermgrcli.dll             10.0.19041.546              UserMgr API DLL
    usermgrproxy.dll           10.0.19041.1741             UserMgrProxy
    usoapi.dll                 10.0.19041.2311             Update Session Orchestrator API
    usp10.dll                  10.0.19041.546              Uniscribe Unicode script processor
    ustprov.dll                10.0.19041.1                User State WMI Provider
    utildll.dll                10.0.19041.1                  WinStation
    uudf.dll                   10.0.19041.1023             UDF Utility DLL
    uxinit.dll                 10.0.19041.2193             Windows User Experience Session Initialization Dll
    uxlib.dll                  10.0.19041.572              Setup Wizard Framework
    uxlibres.dll               10.0.19041.1                UXLib Resources
    uxtheme.dll                10.0.19041.2193               UxTheme (Microsoft)
    van.dll                    10.0.19041.746                
    vault.dll                  10.0.19041.423                -  Windows
    vaultcli.dll               10.0.19041.746                  
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.812.10240.16384           Microsoft  VBScript
    vcamp120.dll               12.0.21005.1                Microsoft C++ AMP Runtime
    vcamp140.dll               14.36.32532.0               Microsoft C++ AMP Runtime
    vcardparser.dll            10.0.19041.746              Supports the parsing of VCard and ICal formatted data
    vccorlib120.dll            12.0.21005.1                Microsoft  VC WinRT core library
    vccorlib140.dll            14.36.32532.0               Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.325              Microsoft C/C++ OpenMP Runtime
    vcomp120.dll               12.0.21005.1                Microsoft C/C++ OpenMP Runtime
    vcomp140.dll               14.36.32532.0               Microsoft C/C++ OpenMP Runtime
    vcruntime140.dll           14.36.32532.0               Microsoft C Runtime Library
    vcruntime140_clr0400.dll   14.10.25028.0               Microsoft C Runtime Library
    vdmdbg.dll                 10.0.19041.1                VDMDBG.DLL
    vds_ps.dll                 10.0.19041.1                Microsoft Virtual Disk Service proxy/stub
    verifier.dll               10.0.19041.1                Standard application verifier provider dll
    version.dll                10.0.19041.546              Version Checking and File Installation Libraries
    vfwwdm32.dll               10.0.19041.1                 VfW MM Driver    WDM-
    vidreszr.dll               10.0.19041.2604             Windows Media Resizer
    virtdisk.dll               10.0.19041.2311             Virtual Disk API DLL
    voiceactivationmanager.dll  10.0.19041.746              Windows Voice Activation Manager
    voiprt.dll                 10.0.19041.746              Voip Runtime
    vpnikeapi.dll              10.0.19041.1                VPN IKE API's
    vscmgrps.dll               10.0.19041.1                Microsoft Virtual Smart Card Manager Proxy/Stub
    vss_ps.dll                 10.0.19041.2846             Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 10.0.19041.1320             Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               10.0.19041.546                    Microsoft
    vulkan-1.dll               1.3.241.0                   Vulkan Loader
    vulkan-1-999-0-0-0.dll     1.3.241.0                   Vulkan Loader
    w32topl.dll                10.0.19041.546              Windows NT Topology Maintenance Tool
    wab32.dll                  10.0.19041.2364             Microsoft (R) Contacts DLL
    wab32res.dll               10.0.19041.2364              Microsoft (R) DLL
    wabsyncprovider.dll        10.0.19041.1                   Microsoft Windows
    walletbackgroundserviceproxy.dll  10.0.19041.1                Wallet Background Proxy
    walletproxy.dll            10.0.19041.1                Wallet proxy
    wavemsp.dll                10.0.19041.1645             Microsoft Wave MSP
    wbemcomn.dll               10.0.19041.1566             WMI
    wcmapi.dll                 10.0.19041.546              Windows Connection Manager Client API
    wcnapi.dll                 10.0.19041.746              Windows Connect Now - API Helper DLL
    wcnwiz.dll                 10.0.19041.746                Windows Connect Now
    wdc.dll                    10.0.19041.1                 
    wdi.dll                    10.0.19041.1                  Windows
    wdigest.dll                10.0.19041.2673             Microsoft Digest Access
    wdscore.dll                10.0.19041.546              Panther Engine Module
    webauthn.dll               10.0.19041.2913             -
    webcamui.dll               10.0.19041.1806               Microsoft Windows
    webcheck.dll               11.0.19041.1                 -
    webclnt.dll                10.0.19041.1566              DLL - DAV
    webio.dll                  10.0.19041.2673             API    
    webplatstorageserver.dll   10.0.19041.2075             "webplatstorageserver.DYNLINK"
    webservices.dll            10.0.19041.546                - Windows
    websocket.dll              10.0.19041.546              Web Socket API
    wecapi.dll                 10.0.19041.662              Event Collector Configuration API
    wer.dll                    10.0.19041.2913                 Windows
    werdiagcontroller.dll      10.0.19041.2913             WER Diagnostic Controller
    werenc.dll                 10.0.19041.2546             Windows Error Reporting Dump Encoding Library
    weretw.dll                 10.0.19041.2913             WERETW.DLL
    werui.dll                  10.0.19041.2546              DLL      Windows
    wevtapi.dll                10.0.19041.2193             API    
    wevtfwd.dll                10.0.19041.1                    WS-Management
    wfapigp.dll                10.0.19041.2913             Windows Defender Firewall GPO Helper dll
    wfdprov.dll                10.0.19041.1202             Private WPS provisioning API DLL for Wi-Fi Direct
    wfhc.dll                   10.0.19041.746                Windows.   
    whhelper.dll               10.0.19041.1                DLL     winHttp
    wiaaut.dll                 10.0.19041.1806              WIA-
    wiadefui.dll               10.0.19041.1806                 WIA
    wiadss.dll                 10.0.19041.1806              WIA -  TWAIN
    wiascanprofiles.dll        10.0.19041.1806             Microsoft Windows ScanProfiles
    wiashext.dll               10.0.19041.1806                    
    wiatrace.dll               10.0.19041.1806             WIA Tracing
    wifidisplay.dll            10.0.19041.1                 DLL   Wi-Fi
    wimgapi.dll                10.0.19041.1202              Windows Imaging
    win32u.dll                 10.0.19041.2913             Win32u
    winbio.dll                 10.0.19041.1387             API   Windows
    winbioext.dll              10.0.19041.1                Windows Biometrics Client Extension API
    winbrand.dll               10.0.19041.1415             Windows Branding Resources
    wincorlib.dll              10.0.19041.2788             Microsoft Windows  WinRT core library
    wincredprovider.dll        10.0.19041.2006             wincredprovider DLL
    wincredui.dll              10.0.19041.2486                 
    windowmanagementapi.dll                                
    windows.accountscontrol.dll  10.0.19041.1806             Windows Accounts Control
    windows.ai.machinelearning.dll  1.0.2007.1310               Windows Machine Learning Runtime
    windows.ai.machinelearning.preview.dll  10.0.19041.746              WinRT Windows Machine Learning Preview DLL
    windows.applicationmodel.background.systemeventsbroker.dll  10.0.19041.1202             Windows Background System Events Broker API Server
    windows.applicationmodel.background.timebroker.dll  10.0.19041.746              Windows Background Time Broker API Server
    windows.applicationmodel.conversationalagent.dll  10.0.19041.2364             Windows Voice Agent Services DLL
    windows.applicationmodel.conversationalagent.internal.proxystub.dll                              
    windows.applicationmodel.conversationalagent.proxystub.dll                              
    windows.applicationmodel.core.dll  10.0.19041.1466             Windows Application Model Core API
    windows.applicationmodel.datatransfer.dll  10.0.19041.746              Windows.ApplicationModel.DataTransfer
    windows.applicationmodel.dll  10.0.19041.2364              API Windows ApplicationModel
    windows.applicationmodel.lockscreen.dll  10.0.19041.746              Windows Lock Application Framework DLL
    windows.applicationmodel.store.dll  10.0.19041.2546             Microsoft Store   DLL  
    windows.applicationmodel.store.preview.dosettings.dll  10.0.19041.2311             Delivery Optimization Settings
    windows.applicationmodel.store.testingframework.dll  10.0.19041.906              Microsoft Store   DLL    
    windows.applicationmodel.wallet.dll  10.0.19041.746              Windows ApplicationModel Wallet Runtime DLL
    windows.data.pdf.dll       10.0.19041.1023             API- PDF WinRT
    windows.devices.alljoyn.dll  10.0.19041.746              Windows.Devices.AllJoyn DLL
    windows.devices.background.dll  10.0.19041.1865             Windows.Devices.Background
    windows.devices.background.ps.dll  10.0.19041.1                Windows.Devices.Background Interface Proxy
    windows.devices.bluetooth.dll  10.0.19041.746              DLL- Windows.Devices.Bluetooth
    windows.devices.custom.dll  10.0.19041.746              Windows.Devices.Custom
    windows.devices.custom.ps.dll  10.0.19041.1                Windows.Devices.Custom Interface Proxy
    windows.devices.enumeration.dll  10.0.19041.1865             Windows.Devices.Enumeration
    windows.devices.haptics.dll  10.0.19041.746              Windows Runtime Haptics DLL
    windows.devices.humaninterfacedevice.dll  10.0.19041.1466             Windows.Devices.HumanInterfaceDevice DLL
    windows.devices.lights.dll  10.0.19041.1741             Windows Runtime Lights DLL
    windows.devices.lowlevel.dll  10.0.19041.746              DLL- Windows.Devices.LowLevel
    windows.devices.midi.dll   10.0.19041.746              Windows Runtime MIDI Device server DLL
    windows.devices.perception.dll  10.0.19041.746              Windows Devices Perception API
    windows.devices.picker.dll  10.0.19041.1826               
    windows.devices.pointofservice.dll  10.0.19041.1806              PointOfService DLL   Windows
    windows.devices.portable.dll  10.0.19041.746              Windows Runtime Portable Devices DLL
    windows.devices.printers.dll  10.0.19041.1806             Windows Runtime Devices Printers DLL
    windows.devices.printers.extensions.dll  10.0.19041.1806             Windows.Devices.Printers.Extensions
    windows.devices.radios.dll  10.0.19041.746              Windows.Devices.Radios DLL
    windows.devices.scanners.dll  10.0.19041.1806              DLL    Windows
    windows.devices.sensors.dll  10.0.19041.2311             Windows Runtime Sensors DLL
    windows.devices.serialcommunication.dll  10.0.19041.746              Windows.Devices.SerialCommunication DLL
    windows.devices.smartcards.dll  10.0.19041.746               DLL API -   Windows
    windows.devices.smartcards.phone.dll  10.0.19041.746              Windows Runtime Phone Smart Card Api DLL
    windows.devices.usb.dll    10.0.19041.746              Windows Runtime Usb DLL
    windows.devices.wifi.dll   10.0.19041.746              Windows.Devices.WiFi DLL
    windows.devices.wifidirect.dll  10.0.19041.746              Windows.Devices.WiFiDirect DLL
    windows.energy.dll         10.0.19041.2075             Windows Energy Runtime DLL
    windows.fileexplorer.common.dll  10.0.19041.1566             Windows.FileExplorer.Common
    windows.gaming.input.dll   10.0.19041.2913             Windows Gaming Input API
    windows.gaming.preview.dll  10.0.19041.1586             Windows Gaming API Preview
    windows.gaming.ui.gamebar.dll  10.0.19041.746              Windows Gaming UI API GameBar
    windows.gaming.xboxlive.storage.dll  10.0.19041.746              Xbox Connected Storage WinRT implementation
    windows.globalization.dll  10.0.19041.1865             Windows Globalization
    windows.globalization.fontgroups.dll  10.0.19041.746              Fonts Mapping API
    windows.globalization.phonenumberformatting.dll  10.0.19041.746              Windows Libphonenumber OSS component
    windows.graphics.display.brightnessoverride.dll  10.0.19041.746              Windows Runtime Brightness Override DLL
    windows.graphics.display.displayenhancementoverride.dll  10.0.19041.906              Windows Runtime Display Enhancement Override DLL
    windows.graphics.dll       10.0.19041.1151             WinRT Windows Graphics DLL
    windows.graphics.printing.3d.dll  10.0.19041.1806             Microsoft Windows Printing Support
    windows.graphics.printing.dll  10.0.19041.1806               Microsoft Windows
    windows.graphics.printing.workflow.dll  10.0.19041.2913             Microsoft Windows Print Workflow
    windows.graphics.printing.workflow.native.dll  10.0.19041.2913             Microsoft Windows Print Workflow Native
    windows.internal.bluetooth.dll  10.0.19041.2728             Windows.Internal.Bluetooth DLL
    windows.internal.devices.sensors.dll  10.0.19041.746              Windows Runtime Sensors (Internal) DLL
    windows.internal.graphics.display.displaycolormanagement.dll  10.0.19041.1566             Windows Runtime Display Color Management DLL
    windows.internal.graphics.display.displayenhancementmanagement.dll  10.0.19041.746              Windows Runtime Display Enhancement Management DLL
    windows.internal.management.dll  10.0.19041.2788              DLL   Windows
    windows.internal.securitymitigationsbroker.dll  10.0.19041.1865                  Windows
    windows.internal.shellcommon.accountscontrolexperience.dll  10.0.19041.746              Shell Position default shell contract handler
    windows.internal.shellcommon.printexperience.dll  10.0.19041.746              Print Experience default shell contract handler
    windows.internal.shellcommon.tokenbrokermodal.dll  10.0.19041.746              Token broker default shell contract handler
    windows.internal.ui.logon.proxystub.dll  10.0.19041.1                Logon User Experience Proxy Stub
    windows.internal.ui.shell.windowtabmanager.dll                              
    windows.management.workplace.dll  10.0.19041.2788             Windows Runtime MdmPolicy DLL
    windows.management.workplace.workplacesettings.dll  10.0.19041.746              Windows Runtime WorkplaceSettings DLL
    windows.media.audio.dll    10.0.19041.1620             Windows Runtime Window Media Audio server DLL
    windows.media.backgroundmediaplayback.dll  10.0.19041.1266             Windows Media BackgroundMediaPlayback DLL
    windows.media.devices.dll  10.0.19041.1865             Windows Runtime media device server DLL
    windows.media.dll          10.0.19041.2075             Windows Media Runtime DLL
    windows.media.editing.dll  10.0.19041.746              Windows Media Editing DLL
    windows.media.faceanalysis.dll  10.0.19041.746              Microsoft (R) Face Detection DLL
    windows.media.import.dll   10.0.19041.2913             Windows Photo Import API (WinRT/COM)
    windows.media.mediacontrol.dll  10.0.19041.746               DLL  MediaControl   Windows
    windows.media.mixedrealitycapture.dll  10.0.19041.746              "Windows.Media.MixedRealityCapture.DYNLINK"
    windows.media.ocr.dll      10.0.19041.746              Windows OCR Runtime DLL
    windows.media.playback.backgroundmediaplayer.dll  10.0.19041.1266             Windows Media Playback BackgroundMediaPlayer DLL
    windows.media.playback.mediaplayer.dll  10.0.19041.1266             Windows Media Playback MediaPlayer DLL
    windows.media.playback.proxystub.dll  10.0.19041.1                BackgroundMediaPlayer Proxy Stub DLL
    windows.media.protection.playready.dll  10.0.19041.2965             Microsoft PlayReady Client Framework Dll
    windows.media.speech.dll   10.0.19041.1806             Windows Speech Runtime DLL
    windows.media.streaming.dll  10.0.19041.1566             DLNA DLL
    windows.media.streaming.ps.dll  10.0.19041.1                DLNA Proxy-Stub DLL
    windows.mirage.dll         10.0.19041.1741             Windows Perception API
    windows.mirage.internal.dll  10.0.19041.1151             "Windows.Mirage.Internal.DYNLINK"
    windows.networking.backgroundtransfer.backgroundmanagerpolicy.dll  10.0.19041.746              Background Transfer Background Manager Policy DLL
    windows.networking.backgroundtransfer.dll  10.0.19041.746              Windows.Networking.BackgroundTransfer DLL
    windows.networking.connectivity.dll  10.0.19041.2311             Windows Networking Connectivity Runtime DLL
    windows.networking.dll     10.0.19041.746              Windows.Networking DLL
    windows.networking.hostname.dll  10.0.19041.2311             Windows.Networking.HostName DLL
    windows.networking.networkoperators.esim.dll  10.0.19041.746              ESIM API
    windows.networking.networkoperators.hotspotauthentication.dll  10.0.19041.746              Microsoft Windows Hotspot Authentication API
    windows.networking.proximity.dll  10.0.19041.746              Windows Runtime Proximity API DLL
    windows.networking.servicediscovery.dnssd.dll  10.0.19041.746              Windows.Networking.ServiceDiscovery.Dnssd DLL
    windows.networking.sockets.pushenabledapplication.dll  10.0.19041.746              Windows.Networking.Sockets.PushEnabledApplication DLL
    windows.networking.vpn.dll  10.0.19041.1806             Windows.Networking.Vpn DLL
    windows.networking.xboxlive.proxystub.dll  10.0.19041.1                Windows.Networking.XboxLive Proxy Stub Dll
    windows.payments.dll       10.0.19041.1806             Payment Windows Runtime DLL
    windows.perception.stub.dll  10.0.19041.1023             API   Windows
    windows.security.authentication.identity.provider.dll  10.0.19041.746              Secondary Factor Authentication Windows Runtime DLL
    windows.security.authentication.onlineid.dll  10.0.19041.746              Windows Runtime OnlineId Authentication DLL
    windows.security.authentication.web.core.dll  10.0.19041.1566             API   WinRT
    windows.security.credentials.ui.credentialpicker.dll  10.0.19041.746              WinRT Credential Picker Server
    windows.security.credentials.ui.userconsentverifier.dll  10.0.19041.1202             API     Windows
    windows.security.integrity.dll  10.0.19041.2006             Windows Lockdown API Server
    windows.services.targetedcontent.dll  10.0.19041.1387             Windows.Services.TargetedContent
    windows.shell.servicehostbuilder.dll  10.0.19041.746              Windows.Shell.ServiceHostBuilder
    windows.staterepository.dll  10.0.19041.2673              Windows StateRepository API Server
    windows.staterepositorybroker.dll  10.0.19041.2673             Windows StateRepository API Broker
    windows.staterepositoryclient.dll  10.0.19041.2673             Windows StateRepository Client API
    windows.staterepositorycore.dll  10.0.19041.2673             Windows StateRepository API Core
    windows.staterepositoryps.dll  10.0.19041.2673             Windows StateRepository Proxy/Stub Server
    windows.staterepositoryupgrade.dll  10.0.19041.2673             Windows StateRepository Upgrade
    windows.storage.applicationdata.dll  10.0.19041.2311             Windows Application Data API Server
    windows.storage.compression.dll  5.0.1.1                     WinRT Compression
    windows.storage.dll        10.0.19041.2788             API  Microsoft WinRT
    windows.storage.onecore.dll  10.0.19041.1237             Microsoft Windows.Storage OneCore API
    windows.storage.search.dll  10.0.19041.2673             Windows.Storage.Search
    windows.system.diagnostics.dll  10.0.19041.746              Windows System Diagnostics DLL
    windows.system.diagnostics.telemetry.platformtelemetryclient.dll  10.0.19041.746              Platform Telemetry Client DLL
    windows.system.diagnostics.tracereporting.platformdiagnosticactions.dll  10.0.19041.746              Platform Diagnostic Actions DLL
    windows.system.launcher.dll  10.0.19041.1503             Windows.System.Launcher
    windows.system.profile.hardwareid.dll  10.0.19041.746              DLL-      Windows
    windows.system.profile.platformdiagnosticsandusagedatasettings.dll  10.0.19041.1081             Platform Diagnostics and Usage Settings DLL
    windows.system.profile.retailinfo.dll  10.0.19041.746              Windows.System.Profile.RetailInfo Runtime DLL
    windows.system.profile.systemid.dll  10.0.19041.746              Windows System Profile SystemId DLL
    windows.system.profile.systemmanufacturers.dll  10.0.19041.1865             Windows.System.Profile.SystemManufacturers
    windows.system.remotedesktop.dll  10.0.19041.746              Windows System RemoteDesktop Runtime DLL
    windows.system.systemmanagement.dll  10.0.19041.746              Windows Runtime SystemManagement DLL
    windows.system.userdeviceassociation.dll  10.0.19041.746              Windows System User Device Association API
    windows.system.userprofile.diagnosticssettings.dll  10.0.19041.746              Diagnostics Settings DLL
    windows.ui.accessibility.dll  10.0.19041.746              Windows.UI.Accessibility System DLL
    windows.ui.core.textinput.dll  10.0.19041.2913             Windows.UI.Core.TextInput dll
    windows.ui.cred.dll        10.0.19041.746              Credential Prompt User Experience
    windows.ui.creddialogcontroller.dll  10.0.19041.964                     
    windows.ui.dll             10.0.19041.746              Windows Runtime UI Foundation DLL
    windows.ui.fileexplorer.dll  10.0.19041.1566             Windows.UI.FileExplorer
    windows.ui.immersive.dll   10.0.19041.2728             WINDOWS.UI.IMMERSIVE
    windows.ui.input.inking.analysis.dll  1.0.1907.3002               
    windows.ui.input.inking.dll  10.0.19041.964              WinRT Windows Inking DLL
    windows.ui.search.dll      10.0.19041.1806             Windows.UI.Search
    windows.ui.xaml.controls.dll  10.0.19041.1023             Windows.UI.Xaml.Controls
    windows.ui.xaml.dll        10.0.19041.2965             Windows.UI.Xaml dll
    windows.ui.xaml.inkcontrols.dll  10.0.19041.1023             API InkControls  XAML  Windows
    windows.ui.xaml.maps.dll   10.0.19041.1023             API  Windows UI XAML
    windows.ui.xaml.phone.dll  10.0.19041.1023             Windows UI XAML Phone API
    windows.ui.xamlhost.dll    10.0.19041.746              XAML Host
    windows.web.diagnostics.dll  10.0.19041.746              Windows.Web.Diagnostics
    windows.web.dll            10.0.19041.746               DLL -
    windows.web.http.dll       10.0.19041.746               DLL Windows.Web.Http
    windowscodecs.dll          10.0.19041.1706             Microsoft Windows Codecs Library
    windowscodecsext.dll       10.0.19041.546              Microsoft Windows Codecs Extended Library
    windowscodecsraw.dll       10.0.19041.2251             Microsoft Camera Codec Pack
    windowsdefaultheatprocessor.dll                              
    windowslivelogin.dll       10.0.19041.746              Microsoft Account Login Helper
    windowsperformancerecordercontrol.dll  10.0.19041.746              Microsoft Windows Performance Recorder Control Library
    winfax.dll                 10.0.19041.2604             Microsoft  Fax API Support DLL
    winhttp.dll                10.0.19041.2673              HTTP Windows
    winhttpcom.dll             10.0.19041.1320             Windows COM interface for WinHttp
    wininet.dll                11.0.19041.2193                Win32
    wininetlui.dll             10.0.19041.1                      wininet
    wininitext.dll             10.0.19041.1620             WinInit Utility Extension DLL
    winipcfile.dll             10.0.19041.1766             Microsoft Active Directory Rights Management Services File API
    winipcsecproc.dll          10.0.19041.1766             Microsoft Active Directory Rights Management Services Desktop Security Processor
    winipsec.dll               10.0.19041.1682             Windows IPsec SPD Client DLL
    winlangdb.dll              10.0.19041.1806                Windows Bcp47
    winml.dll                  10.0.19041.1                Windows Machine Learning Runtime
    winmm.dll                  10.0.19041.546              MCI API DLL
    winmmbase.dll              10.0.19041.1                  API  
    winmsipc.dll               10.0.19041.1766                 Active Directory (Microsoft)
    winmsoirmprotector.dll     10.0.19041.746              Windows Office file format IRM Protector
    winnlsres.dll              10.0.19041.1                 NLSBuild
    winnsi.dll                 10.0.19041.546              Network Store Information RPC interface
    winopcirmprotector.dll     10.0.19041.746              Windows Office file format IRM Protector
    winrnr.dll                 10.0.19041.546              LDAP RnR Provider DLL
    winrscmd.dll               10.0.19041.1081             remtsvc
    winrsmgr.dll               10.0.19041.1                WSMan Shell API
    winrssrv.dll               10.0.19041.1                winrssrv
    winrttracing.dll           10.0.19041.746              Windows Diagnostics Tracing
    winsatapi.dll              10.0.19041.1320             Windows System Assessment Tool API
    winscard.dll               10.0.19041.844              API - (Microsoft)
    winshfhc.dll               10.0.19041.662              File Risk Estimation
    winsku.dll                 10.0.19041.1415             Windows SKU Library
    winsockhc.dll              10.0.19041.746                   Winsock
    winsqlite3.dll             3.29.0.0                    SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine.
    winsrpc.dll                10.0.19041.1                WINS RPC LIBRARY
    winsta.dll                 10.0.19041.2075             Winstation Library
    winsync.dll                2007.94.19041.1             Synchronization Framework
    winsyncmetastore.dll       2007.94.19041.1             Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.19041.1             Windows Synchronization Provider Framework
    wintrust.dll               10.0.19041.2913             Microsoft Trust Verification APIs
    wintypes.dll               10.0.19041.2788              DLL   Windows
    winusb.dll                 10.0.19041.1                Windows USB Driver User Library
    wisp.dll                   10.0.19041.746              Microsoft Pen and Touch Input Component
    wkscli.dll                 10.0.19041.1645             Workstation Service Client DLL
    wkspbrokerax.dll           10.0.19041.746              Microsoft Workspace Broker ActiveX Control
    wksprtps.dll               10.0.19041.1                WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                10.0.19041.1237             Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                10.0.19041.1237              DLL    Netsh  WLAN
    wlanconn.dll               10.0.19041.746                Dot11
    wlandlg.dll                10.0.19041.746                   
    wlangpui.dll               10.0.19041.746               "   "
    wlanhlp.dll                10.0.19041.1202             Windows Wireless LAN 802.11 Client Side Helper API
    wlanmm.dll                 10.0.19041.746                Dot11   
    wlanpref.dll               10.0.19041.746                
    wlanui.dll                 10.0.19041.1202                
    wlanutil.dll               10.0.19041.1                 DLL     Windows   802.11
    wldap32.dll                10.0.19041.2006             Win32 LDAP API DLL
    wldp.dll                   10.0.19041.2788               Windows
    wlgpclnt.dll               10.0.19041.488                 802.11
    wlidcli.dll                10.0.19041.746                 (DLL)   
    wlidcredprov.dll           10.0.19041.746              Microsoft Account Credential Provider
    wlidfdp.dll                10.0.19041.746              Microsoft Account Function Discovery Provider
    wlidnsp.dll                10.0.19041.423              Microsoft Account Namespace Provider
    wlidprov.dll               10.0.19041.746              Microsoft Account Provider
    wlidres.dll                10.0.19041.1                 Microsoft Windows Live ID
    wmadmod.dll                10.0.19041.1288             Windows Media Audio Decoder
    wmadmoe.dll                10.0.19041.508              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.19041.1                Windows Media ASF DLL
    wmcodecdspps.dll           10.0.19041.1                Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.19041.746              Windows Media Device Manager Logger
    wmdmps.dll                 12.0.19041.1                Windows Media Device Manager Proxy Stub
    wmdrmsdk.dll               10.0.19041.1                WMDRM backwards compatibility stub
    wmerror.dll                12.0.19041.1                  Windows Media ()
    wmi.dll                    10.0.19041.1                WMI DC and DP functionality
    wmiclnt.dll                10.0.19041.546              WMI Client API
    wmidcom.dll                10.0.19041.546              WMI
    wmidx.dll                  12.0.19041.746              Windows Media Indexer DLL
    wmiprop.dll                10.0.19041.1                    WDM
    wmitomi.dll                10.0.19041.1                  CIM
    wmnetmgr.dll               12.0.19041.746              Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.19041.1865             Windows Media Player
    wmpdxm.dll                 12.0.19041.1266             Windows Media Player Extension
    wmpeffects.dll             12.0.19041.1266             Windows Media Player Effects
    wmphoto.dll                10.0.19041.867               Windows Media
    wmploc.dll                 12.0.19041.1266               Windows Media
    wmpps.dll                  12.0.19041.1                Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.19041.1266                Windows Media
    wmsgapi.dll                10.0.19041.546              WinLogon IPC Client
    wmspdmod.dll               10.0.19041.1                Windows Media Audio Voice Decoder
    wmspdmoe.dll               10.0.19041.508              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.19041.2604             Windows Media Playback/Authoring DLL
    wmvdecod.dll               10.0.19041.2604                 Windows Media
    wmvdspa.dll                10.0.19041.746              Windows Media Video DSP Components - Advanced
    wmvencod.dll               10.0.19041.1                    Windows Media 9
    wmvsdecd.dll               10.0.19041.1                Windows Media Screen Decoder
    wmvsencd.dll               10.0.19041.1                Windows Media Screen Encoder
    wmvxencd.dll               10.0.19041.867              Windows Media Video Encoder
    wofutil.dll                10.0.19041.1                Windows Overlay File System Filter user mode API
    wordbreakers.dll           10.0.19041.2913             "WordBreakers.DYNLINK"
    workfoldersres.dll         6.2.9200.16384                
    wow32.dll                  10.0.19041.1023             Wow32
    wpbcreds.dll               10.0.19041.1                WP 8.1 upgrade support utility
    wpc.dll                    10.0.19041.1566                
    wpcwebfilter.dll           10.0.19041.964              WpcWebFilter.dll
    wpdshext.dll               10.0.19041.1949                 
    wpdshserviceobj.dll        10.0.19041.1949             Windows Portable Device Shell Service Object
    wpdsp.dll                  10.0.19041.746              WMDM Service Provider for Windows Portable Devices
    wpnapps.dll                10.0.19041.2546               push- Windows
    wpnclient.dll              10.0.19041.1806             Windows Push Notifications Client
    wpportinglibrary.dll       10.0.19041.1                <d> DLL
    ws2_32.dll                 10.0.19041.546              32-  Windows Socket 2.0
    ws2help.dll                10.0.19041.1                Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 10.0.19041.2673             API    Windows
    wscinterop.dll             10.0.19041.1081             Windows Health Center WSC Interop
    wscisvif.dll               10.0.19041.2673             Windows Security Center ISV API
    wsclient.dll               10.0.19041.1                Microsoft Store Licensing Client
    wscproxystub.dll           10.0.19041.2673             Windows Security Center ISV Proxy Stub
    wsdapi.dll                 10.0.19041.1806             -   DLL API- 
    wsdchngr.dll               10.0.19041.1                WSD Challenge Component
    wsdproviderutil.dll                                    
    wsecedit.dll               10.0.19041.2913                
    wshbth.dll                 10.0.19041.546              Windows Sockets Helper DLL
    wshcon.dll                 5.812.10240.16384           Microsoft  Windows Script Controller
    wshelper.dll               10.0.19041.1                 DLL    Winsock Net
    wshext.dll                 5.812.10240.16384           Microsoft  Shell Extension for Windows Script Host
    wshhyperv.dll              10.0.19041.1                Hyper-V Winsock2 Helper DLL
    wship6.dll                 10.0.19041.546               DLL  Winsock2 (TL/IPv6)
    wshqos.dll                 10.0.19041.546               DLL   QoS Winsock2
    wshrm.dll                  10.0.19041.2846               DLL   Windows  PGM
    wshtcpip.dll               10.0.19041.546               DLL   Winsock2 (TL/IPv4)
    wshunix.dll                10.0.19041.1                AF_UNIX Winsock2 Helper DLL
    wsmagent.dll               10.0.19041.2193             WinRM Agent
    wsmanmigrationplugin.dll   10.0.19041.2193             WinRM Migration Plugin
    wsmauto.dll                10.0.19041.2193             WSMAN Automation
    wsmplpxy.dll               10.0.19041.2193             wsmplpxy
    wsmres.dll                 10.0.19041.2193              DLL  WSMan
    wsmsvc.dll                 10.0.19041.2193              WSMan
    wsmwmipl.dll               10.0.19041.2193             WSMAN WMI Provider
    wsnmp32.dll                10.0.19041.1                Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                10.0.19041.1                Windows Socket 32-Bit DLL
    wsp_fs.dll                 10.0.19041.2913             Windows Storage Provider for FileShare management
    wsp_health.dll             10.0.19041.2913             Windows Storage Provider for Health Agent API
    wsp_sr.dll                 10.0.19041.1                Windows Storage Provider for Storage Replication management
    wtsapi32.dll               10.0.19041.546              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  10.0.19041.2788             API    Windows
    wuceffects.dll             10.0.19041.546              Microsoft Composition Effects
    wudriver.dll               10.0.19041.2788             Windows Update WUDriver Stub
    wups.dll                   10.0.19041.2788             Windows Update client proxy stub
    wvc.dll                    1.0.0.1                     Windows Visual Components
    wwaapi.dll                 10.0.19041.1806             Microsoft Web Application Host API library
    wwaext.dll                 10.0.19041.746              Microsoft Web Application Host Extension library
    wwanapi.dll                10.0.19041.746              Mbnapi
    wwapi.dll                  10.0.19041.546              WWAN API
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xaudio2_8.dll              10.0.19041.1                XAudio2 Game Audio API
    xaudio2_9.dll              10.0.19041.2913             XAudio2 Game Audio API
    xblauthmanagerproxy.dll    10.0.19041.1586             XblAuthManagerProxy
    xblauthtokenbrokerext.dll  10.0.19041.1586             Xbox Live Token Broker Extension
    xblgamesaveproxy.dll       10.0.19041.1                Xbox Live Game Save Service Proxies and Stubs
    xboxgipsynthetic.dll                                   
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput1_4.dll              10.0.19041.844              API   ()
    xinput9_1_0.dll            10.0.19041.1                  XNA
    xinputuap.dll              10.0.19041.2913             Microsoft Common Controller API
    xmlfilter.dll              2008.0.19041.746             XML
    xmllite.dll                10.0.19041.546              Microsoft XmlLite Library
    xmlprovi.dll               10.0.19041.746              Network Provisioning Service Client API
    xmlrw.dll                  2011.110.9165.1186          XMLRW
    xmlrwbin.dll               2011.110.9165.1186          XMLRWBIN
    xolehlp.dll                2001.12.10941.16384         Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsdocumenttargetprint.dll  10.0.19041.1806             XPS DocumentTargetPrint DLL
    xpsgdiconverter.dll        10.0.19041.1806             XPS to GDI Converter
    xpsprint.dll               10.0.19041.2788             XPS Printing DLL
    xpspushlayer.dll           10.0.19041.1806             Xps Push Layer Component
    xpsrasterservice.dll       10.0.19041.1806             XPS Rasterization Service Component
    xpsservices.dll            10.0.19041.2364             Xps Object Model in memory creation and deserialization
    xpstopclmconverter.dll     10.0.19041.1806             XPS to PCLm Converter
    xpstopwgrconverter.dll     10.0.19041.1806             XPS to PWGR Converter
    xwizards.dll               10.0.19041.746                 
    xwreg.dll                  10.0.19041.746              Extensible Wizard Registration Manager Module
    xwtpdui.dll                10.0.19041.746                   DUI
    xwtpw32.dll                10.0.19041.746                   Win32
    zipcontainer.dll           10.0.19041.1                Zip Container DLL
    zipfldr.dll                10.0.19041.789               ZIP-
    ztrace_maps.dll            10.0.19041.1                ZTrace Event Resources


--------[   ]------------------------------------------------------------------------------------------------

     :
                         19.07.2023 10:23:14
                           19.07.2023 13:59:54
                                            19.07.2023 22:03:05
                                             28991  (0 ., 8 , 3 , 11 )

      :
                                     18.07.2023 22:10:10
                            18.07.2023 22:11:23
                                        40259  (0 ., 11 , 10 , 59 )
                                       45716  (0 ., 12 , 41 , 56 )
                                  28991  (0 ., 8 , 3 , 11 )
                                 32687  (0 ., 9 , 4 , 47 )
                                       4
                                46.83%

      (" "):
                                              0

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    ADMIN$                                    Admin                           C:\WINDOWS
    C$                                                           C:\
    [ TRIAL VERSION ]               [ TRIAL VERSION ]  [ TRIAL VERSION ]                         [ TRIAL VERSION ]
    IPC$                            IPC            IPC                             


--------[    ]----------------------------------------------------------------------------------------------

                                         ALEXANDER_PC              ALEXANDER_PC
                                         ALEXANDER_PC              ALEXANDER_PC


--------[  ]------------------------------------------------------------------------------------------------

  [ DefaultAccount ]

     :
                                         DefaultAccount
                                               DefaultAccount
                                               ,  .
                                                   ; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ WDAGUtilityAccount ]

     :
                                         WDAGUtilityAccount
                                               WDAGUtilityAccount
                                               ,        Application Guard   Windows.
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               ; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                               ; 
                                     186
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               ; 
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ NVIDIA GeForce RTX 3060 ]

     :
                                      NVIDIA GeForce RTX 3060
                                          NVIDIA GeForce RTX 3060
       BIOS                                       Version94.6.25.40.5
                                      NVIDIA GeForce RTX 3060
       DAC                                           Integrated RAMDAC
                                            12.07.2023
                                          31.0.15.3667 - nVIDIA Detonator 36.67
                                       NVIDIA
                                           12 

     :
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce RTX 3060 ]

     :
                                      NVIDIA GeForce RTX 3060
                                          NVIDIA GeForce RTX 3060
       BIOS                                       Version94.6.25.40.5
                                      NVIDIA GeForce RTX 3060
       DAC                                           Integrated RAMDAC
                                            12.07.2023
                                          31.0.15.3667 - nVIDIA Detonator 36.67
                                       NVIDIA
                                           12 

     :
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce RTX 3060 ]

     :
                                      NVIDIA GeForce RTX 3060
                                          NVIDIA GeForce RTX 3060
       BIOS                                       Version94.6.25.40.5
                                      NVIDIA GeForce RTX 3060
       DAC                                           Integrated RAMDAC
                                            12.07.2023
                                          31.0.15.3667 - nVIDIA Detonator 36.67
                                       NVIDIA
                                           12 

     :
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce RTX 3060 ]

     :
                                      NVIDIA GeForce RTX 3060
                                          NVIDIA GeForce RTX 3060
       BIOS                                       Version94.6.25.40.5
                                      NVIDIA GeForce RTX 3060
       DAC                                           Integrated RAMDAC
                                            12.07.2023
                                          31.0.15.3667 - nVIDIA Detonator 36.67
                                       NVIDIA
                                           12 

     :
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumdx.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll
      C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_14c40086f8e718c9\nvldumd.dll

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[   ]---------------------------------------------------------------------------------------

  [ nVIDIA SLI ]

    nVIDIA SLI:
       SLI                                        


--------[  ]-----------------------------------------------------------------------------------------------------

  [ Dell E2216H (DP) ]

     :
                                             Dell E2216H (DP)
      ID                                        DELF069
                                                  DELL E2216H
                                             21.5" LCD (FHD)
                                              4 / 2016
                                           XV9JN61LAAWS
      .                         476 mm x 268 mm (21.5")
                                       16:9
                                                 250 cd/m2
                                           1000:1
                                              170/160
                                                   DSub, DisplayPort
                                            30 - 83 
                                           56 - 76 
                           170 
                                  1920 x 1080
                                                   2.20
        DPMS                        Active-Off

     :
      640 x 480                                         60 
      640 x 480                                         75 
      720 x 400                                         70 
      800 x 600                                         60 
      800 x 600                                         75 
      1024 x 768                                        60 
      1024 x 768                                        75 
      1152 x 864                                        75 
      1280 x 1024                                       60 
      1280 x 1024                                       75 
      1600 x 900                                        60 
      1920 x 1080                                       60 
      1920 x 1080                                        : 148.50 

     :
                                                   Dell Computer Corporation
                                     http://accessories.us.dell.com/sna/category.aspx?c=us&category_id=4009&cs=19&l=en&s=dhs
                                       http://support.dell.com/support/topics/global.aspx/support/product_support/en/monitor_download?c=us&cs=04&l=en&s=bsd
                                     http://www.aida64.com/driver-updates

  [   PnP [NoDB] ]

     :
                                               PnP [NoDB]
      ID                                        MSI3CA7
                                                  MSI G273
                                              15 / 2022
                                           CA7A472308845
      .                         597 mm x 336 mm (27.0")
                                       16:9
                                            167 
                                           48 - 165 
                           600 
                                                   2.20
        DPMS                        Standby, Suspend, Active-Off

     :
      640 x 480                                         60 
      640 x 480                                         67 
      640 x 480                                         72 
      640 x 480                                         75 
      800 x 600                                         56 
      800 x 600                                         60 
      800 x 600                                         72 
      800 x 600                                         75 
      1024 x 768                                        60 
      1024 x 768                                        72 
      1024 x 768                                        75 
      1280 x 1024                                       60 
      1280 x 1024                                       75 
      1440 x 900                                        60 
      1680 x 1050                                       60 
      1920 x 1080                                       60 
      1920 x 1080                                        : 136.51 


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1920 x 1080
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      165 
                                    C:\Users\\Desktop\ \1675426607_gas-kvas-com-p-fonovii-risunok-dlya-rabochego-stola-kosmo-15.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1920,1080)
    \\.\DISPLAY2          (-1920,0)      (0,1080)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480          32   100 Hz
    640 x 480          32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   119 Hz
    640 x 480          32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   120 Hz
    640 x 480          32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   144 Hz
    640 x 480          32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   165 Hz
    640 x 480          32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   59 Hz
    640 x 480          32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    640 x 480          32   75 Hz
    720 x 480          32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   100 Hz
    720 x 480          32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   119 Hz
    720 x 480          32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   120 Hz
    720 x 480          32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   144 Hz
    720 x 480          32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 480          32   165 Hz
    720 x 480          32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   100 Hz
    720 x 576          32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   119 Hz
    720 x 576          32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   120 Hz
    720 x 576          32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   144 Hz
    720 x 576          32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   165 Hz
    720 x 576          32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    720 x 576          32   50 Hz
    800 x 600          32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   100 Hz
    800 x 600          32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   119 Hz
    800 x 600          32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   120 Hz
    800 x 600          32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   144 Hz
    800 x 600          32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   165 Hz
    800 x 600          32   56 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    800 x 600          32   72 Hz
    800 x 600          32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   100 Hz
    1024 x 768         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   119 Hz
    1024 x 768         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   120 Hz
    1024 x 768         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   144 Hz
    1024 x 768         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   165 Hz
    1024 x 768         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1024 x 768         32   70 Hz
    1024 x 768         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   100 Hz
    1152 x 864         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   119 Hz
    1152 x 864         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   120 Hz
    1152 x 864         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   144 Hz
    1152 x 864         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   165 Hz
    1152 x 864         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   60 Hz
    1152 x 864         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1152 x 864         32   75 Hz
    1152 x 864         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1176 x 664         32   50 Hz
    1176 x 664         32   50 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1176 x 664         32   59 Hz
    1176 x 664         32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1176 x 664         32   60 Hz
    1176 x 664         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   100 Hz
    1280 x 720         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   119 Hz
    1280 x 720         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   120 Hz
    1280 x 720         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   144 Hz
    1280 x 720         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   165 Hz
    1280 x 720         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 720         32   59 Hz
    1280 x 720         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   100 Hz
    1280 x 768         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   119 Hz
    1280 x 768         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   120 Hz
    1280 x 768         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   144 Hz
    1280 x 768         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   165 Hz
    1280 x 768         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 768         32   75 Hz
    1280 x 768         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   100 Hz
    1280 x 800         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   119 Hz
    1280 x 800         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   120 Hz
    1280 x 800         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   144 Hz
    1280 x 800         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   165 Hz
    1280 x 800         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   60 Hz
    1280 x 800         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 800         32   75 Hz
    1280 x 800         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   100 Hz
    1280 x 960         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   119 Hz
    1280 x 960         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   120 Hz
    1280 x 960         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   144 Hz
    1280 x 960         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   165 Hz
    1280 x 960         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   60 Hz
    1280 x 960         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 960         32   75 Hz
    1280 x 960         32   75 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   100 Hz
    1280 x 1024        32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   119 Hz
    1280 x 1024        32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   120 Hz
    1280 x 1024        32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   144 Hz
    1280 x 1024        32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   165 Hz
    1280 x 1024        32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1280 x 1024        32   75 Hz
    1360 x 768         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   100 Hz
    1360 x 768         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   119 Hz
    1360 x 768         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   120 Hz
    1360 x 768         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   144 Hz
    1360 x 768         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   165 Hz
    1360 x 768         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1360 x 768         32   60 Hz
    1366 x 768         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   100 Hz
    1366 x 768         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   119 Hz
    1366 x 768         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   120 Hz
    1366 x 768         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   144 Hz
    1366 x 768         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   165 Hz
    1366 x 768         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1366 x 768         32   60 Hz
    1440 x 900         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 900         32   100 Hz
    1440 x 900         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 900         32   119 Hz
    1440 x 900         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 900         32   120 Hz
    1440 x 900         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 900         32   144 Hz
    1440 x 900         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 900         32   165 Hz
    1440 x 900         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   100 Hz
    1440 x 1080        32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   119 Hz
    1440 x 1080        32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   120 Hz
    1440 x 1080        32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   144 Hz
    1440 x 1080        32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   165 Hz
    1440 x 1080        32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   50 Hz
    1440 x 1080        32   50 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   59 Hz
    1440 x 1080        32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   60 Hz
    1440 x 1080        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1440 x 1080        32   85 Hz
    1440 x 1080        32   85 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   100 Hz
    1600 x 900         32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   119 Hz
    1600 x 900         32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   120 Hz
    1600 x 900         32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   144 Hz
    1600 x 900         32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   165 Hz
    1600 x 900         32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   59 Hz
    1600 x 900         32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 900         32   60 Hz
    1600 x 900         32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   100 Hz
    1600 x 1024        32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   119 Hz
    1600 x 1024        32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   120 Hz
    1600 x 1024        32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   144 Hz
    1600 x 1024        32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   165 Hz
    1600 x 1024        32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   59 Hz
    1600 x 1024        32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1600 x 1024        32   60 Hz
    1600 x 1024        32   60 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   100 Hz
    1680 x 1050        32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   119 Hz
    1680 x 1050        32   119 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   120 Hz
    1680 x 1050        32   120 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   144 Hz
    1680 x 1050        32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   165 Hz
    1680 x 1050        32   165 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1680 x 1050        32   60 Hz
    1920 x 1080        32   100 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080        32   120 Hz
    1920 x 1080        32   144 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080        32   50 Hz
    1920 x 1080        32   59 Hz
    [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    1920 x 1080        32   85 Hz


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ CUDA: NVIDIA GeForce RTX 3060 ]

     :
                                           NVIDIA GeForce RTX 3060
      PCI Domain / Bus / Device                         0 / 7 / 0
                                                 1837 
      Asynchronous Engines                              5
       L2                                            2304 
      Max Threads Per Multiprocessor                    1536
      Max Threads Per Block                             1024
      Max Registers Per Block                           65536
      Max 32-bit Registers Per Multiprocessor           65536
      Max Instructions Per Kernel                       512 .
      Warp Size                                         32 threads
      Max Block Size                                    1024 x 1024 x 64
      Max Grid Size                                     2147483647 x 65535 x 65535
      Max 1D Texture Width                              131072
      Max 2D Texture Size                               131072 x 65536
      Max 3D Texture Size                               16384 x 16384 x 16384
      Max 1D Linear Texture Width                       268435456
      Max 2D Linear Texture Size                        131072 x 65000
      Max 2D Linear Texture Pitch                       2097120 
      Max 1D Layered Texture Width                      32768
      Max 1D Layered Texture Layers                     2048
      Max Mipmapped 1D Texture Width                    32768
      Max Mipmapped 2D Texture Size                     32768 x 32768
      Max Cubemap Texture Size                          32768 x 32768
      Max Cubemap Layered Texture Size                  32768 x 32768
      Max Cubemap Layered Texture Layers                2046
      Max Texture Array Size                            32768 x 32768
      Max Texture Array Slices                          2048
      Max 1D Surface Width                              32768
      Max 2D Surface Size                               131072 x 65536
      Max 3D Surface Size                               16384 x 16384 x 16384
      Max 1D Layered Surface Width                      32768
      Max 1D Layered Surface Layers                     2048
      Max 2D Layered Surface Size                       32768 x 32768
      Max 2D Layered Surface Layers                     2048
      Compute Mode                                      Default: Multiple contexts allowed per device
      Compute Capability                                8.6
      CUDA DLL                                          nvcuda.dll (31.0.15.3667 - nVIDIA Detonator 36.67)

     :
                                           7501 
      Global Memory Bus Width                           192 
      Total Memory                                      4095 
      Total Constant Memory                             64 
      Max Shared Memory Per Block                       48 
      Max Shared Memory Per Multiprocessor              100 
      Max Memory Pitch                                  2147483647 
      Texture Alignment                                 512 
      Texture Pitch Alignment                           32 
      Surface Alignment                                 512 

     :
      32-bit Floating-Point Atomic Addition             
      32-bit Integer Atomic Operations                  
      64-bit Integer Atomic Operations                  
      Caching Globals in L1 Cache                       
      Caching Locals in L1 Cache                        
      Concurrent Kernel Execution                       
      Concurrent Memory Copy & Execute                  
      Double-Precision Floating-Point                   
      ECC                                               
      Funnel Shift                                      
      Host Memory Mapping                               
      Integrated Device                                 
      Managed Memory                                     
      Multi-GPU Board                                   
      Stream Priorities                                 
      Surface Functions                                 
      TCC Driver                                        
      Warp Vote Functions                               
      __ballot()                                        
      __syncthreads_and()                               
      __syncthreads_count()                             
      __syncthreads_or()                                
      __threadfence_system()                            

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Direct3D: NVIDIA GeForce RTX 3060 ]

     :
                                           NVIDIA GeForce RTX 3060
      PCI-                                    10DE-2504 / 1458-4074  (Rev A1)
                                        3 
                                             nvldumd.dll
                                          31.0.15.3667 - nVIDIA Detonator 36.67
      Shader Model                                      SM 5.1
      Max Threads                                       1024
      Multiple UAV Access                               64 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      10-bit Precision Floating-Point                    
      16-bit Precision Floating-Point                   
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         
      Map On Default Buffers                            

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ OpenCL: NVIDIA GeForce RTX 3060 ]

     OpenCL:
                                               NVIDIA CUDA
                                      NVIDIA Corporation
                                         OpenCL 3.0 CUDA 12.2.128
                                        Full

     :
                                           NVIDIA GeForce RTX 3060
                                            
                                     NVIDIA Corporation
                                        OpenCL 3.0 CUDA
                                       Full
                                          536.67
       OpenCL C                                   OpenCL C 1.2 
                                                 1837 
                                   28
      Address Space Size                                32 
      Max 2D Image Size                                 32768 x 32768
      Max 3D Image Size                                 16384 x 16384 x 16384
      Max Image Array Size                              2048
      Max Image Buffer Size                             268435456
      Max Samplers                                      32
      Max Work-Item Size                                1024 x 1024 x 64
      Max Work-Group Size                               1024
      Max Argument Size                                 32764 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            9
      Max Printf Buffer Size                            1 
      Native ISA Vector Widths                          char1, short1, int1, float1, double1
      Preferred Native Vector Widths                    char1, short1, int1, long1, float1, double1
      Profiling Timer Resolution                        1000 ns
      CUDA Compute Capability                           8.6
      Max Registers Per Block                           65536
      Warp Size                                         32 threads
      Asynchronous Engines                              5
      PCI Bus / Device                                  7 / 0
      OpenCL DLL                                        opencl.dll (3.0.3.0)

     :
      Global Memory                                     12287 
      Global Memory Cache                               784   (Read/Write, 128-byte line)
      Local Memory                                      48 
      Max Memory Object Allocation Size                 3145568 
      Memory Base Address Alignment                     4096 
      Min Data Type Alignment                           128 

     OpenCL:
      OpenCL 1.1                                          (100%)
      OpenCL 1.2                                          (100%)
      OpenCL 2.0                                          (75%)

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler Available                                
                                          
      Images                                            
      Kernel Execution                                  
      Linker Available                                  
      Little-Endian Device                              
      Native Kernel Execution                            
      Sub-Group Independent Forward Progress             
      SVM Atomics                                        
      SVM Coarse Grain Buffer                           
      SVM Fine Grain Buffer                             
      SVM Fine Grain System                              
      Thread Trace                                       
      Unified Memory                                    

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                            
      IEEE754-2008 FMA                                   
      INF and NaNs                                       
      Rounding to Infinity                               
      Rounding to Nearest Even                           
      Rounding to Zero                                   
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                 
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

         :
      Correctly Rounded Divide and Sqrt                  
      Denorms                                           
      IEEE754-2008 FMA                                  
      INF and NaNs                                      
      Rounding to Infinity                              
      Rounding to Nearest Even                          
      Rounding to Zero                                  
      Software Basic Floating-Point Operations          

     :
       /                   100 / 25
      cl_altera_compiler_mode                            
      cl_altera_device_temperature                       
      cl_altera_live_object_tracking                     
      cl_amd_bus_addressable_memory                      
      cl_amd_c1x_atomics                                 
      cl_amd_compile_options                             
      cl_amd_core_id                                     
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                      
      cl_amd_device_board_name                           
      cl_amd_device_memory_flags                         
      cl_amd_device_persistent_memory                    
      cl_amd_device_profiling_timer_offset               
      cl_amd_device_topology                             
      cl_amd_event_callback                              
      cl_amd_fp64                                        
      cl_amd_hsa                                         
      cl_amd_image2d_from_buffer_read_only               
      cl_amd_media_ops                                   
      cl_amd_media_ops2                                  
      cl_amd_offline_devices                             
      cl_amd_popcnt                                      
      cl_amd_predefined_macros                           
      cl_amd_printf                                      
      cl_amd_svm                                         
      cl_amd_vec3                                        
      cl_apple_contextloggingfunctions                   
      cl_apple_gl_sharing                                
      cl_apple_setmemobjectdestructor                    
      cl_arm_core_id                                     
      cl_arm_printf                                      
      cl_ext_atomic_counters_32                          
      cl_ext_atomic_counters_64                          
      cl_ext_device_fission                              
      cl_ext_migrate_memobject                           
      cl_intel_accelerator                               
      cl_intel_advanced_motion_estimation                
      cl_intel_ctz                                       
      cl_intel_d3d11_nv12_media_sharing                  
      cl_intel_device_partition_by_names                 
      cl_intel_dx9_media_sharing                         
      cl_intel_exec_by_local_thread                      
      cl_intel_motion_estimation                         
      cl_intel_printf                                    
      cl_intel_simultaneous_sharing                      
      cl_intel_subgroups                                 
      cl_intel_thread_local_exec                         
      cl_intel_va_api_media_sharing                      
      cl_intel_visual_analytics                          
      cl_khr_3d_image_writes                            
      cl_khr_byte_addressable_store                     
      cl_khr_context_abort                               
      cl_khr_d3d10_sharing                              
      cl_khr_d3d11_sharing                               
      cl_khr_depth_images                                
      cl_khr_device_uuid                                
      cl_khr_dx9_media_sharing                           
      cl_khr_egl_event                                   
      cl_khr_egl_image                                   
      cl_khr_external_memory                            
      cl_khr_external_memory_win32                      
      cl_khr_external_semaphore                         
      cl_khr_external_semaphore_win32                   
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_depth_images                             
      cl_khr_gl_event                                    
      cl_khr_gl_msaa_sharing                             
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                        
      cl_khr_il_program                                  
      cl_khr_image2d_from_buffer                         
      cl_khr_initialize_memory                           
      cl_khr_int64_base_atomics                         
      cl_khr_int64_extended_atomics                     
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_mipmap_image                                
      cl_khr_mipmap_image_writes                         
      cl_khr_pci_bus_info                               
      cl_khr_priority_hints                              
      cl_khr_select_fprounding_mode                      
      cl_khr_spir                                        
      cl_khr_srgb_image_writes                           
      cl_khr_subgroups                                   
      cl_khr_terminate_context                           
      cl_khr_throttle_hints                              
      cl_nv_compiler_options                            
      cl_nv_copy_opts                                   
      cl_nv_create_buffer                               
      cl_nv_d3d10_sharing                               
      cl_nv_d3d11_sharing                               
      cl_nv_d3d9_sharing                                 
      cl_nv_device_attribute_query                      
      cl_nv_pragma_unroll                               
      cl_qcom_ext_host_ptr                               
      cl_qcom_ion_host_ptr                               

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      FFFF FFFF  Headset Earphone (CONEXANT USB 
    mixer.1      0001 0068  MSI G273 (NVIDIA High Definitio
    mixer.2      0001 0068   (Realtek(R) Audio)
    mixer.3      FFFF FFFF   (HyperX Quadcast)
    mixer.4      0001 0068  Realtek Digital Output (Realtek
    mixer.5      FFFF FFFF  Headset Microphone (CONEXANT US
    mixer.6      FFFF FFFF  Microphone (HyperX Quadcast)
    wave-in.0    FFFF FFFF  Microphone (HyperX Quadcast)
    wave-in.1    FFFF FFFF  Headset Microphone (CONEXANT US
    wave-out.0   FFFF FFFF  Headset Earphone (CONEXANT USB 
    wave-out.1   0001 0064  MSI G273 (NVIDIA High Definitio
    wave-out.2   0001 0064   (Realtek(R) Audio)
    wave-out.3   FFFF FFFF   (HyperX Quadcast)
    wave-out.4   0001 0064  Realtek Digital Output (Realtek


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    nVIDIA Unknown @  High Definition Audio (Microsoft) [10DE-228E] [NoDB]  PCI
    Realtek ALC892 @ AMD K17 - High Definition Audio Controller                       PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ AMD K17 - High Definition Audio Controller ]

     :
                                      AMD K17 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        9 / 0 / 3
      ID                                      1022-1457
                               1458-A182
                                                  00
       ID                                     PCI\VEN_1022&DEV_1457&SUBSYS_A1821458&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us/products/desktop/chipsets
                                       http://support.amd.com
       BIOS                                 http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Realtek ALC892 ]

     :
                                      Realtek ALC892
        (Windows)                     Realtek(R) Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0892
                               1458-A182
                                                  1003
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0892&SUBSYS_1458A182&REV_1003

     :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [  High Definition Audio (Microsoft) [10DE-228E] [NoDB] ]

     :
                                       High Definition Audio (Microsoft) [10DE-228E] [NoDB]
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        7 / 0 / 1
      ID                                      10DE-228E
                               1458-4074
                                                  A1
       ID                                     PCI\VEN_10DE&DEV_228E&SUBSYS_40741458&REV_A1

  [ nVIDIA Unknown ]

     :
                                      nVIDIA Unknown
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-009F
                               1458-4074
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_009F&SUBSYS_14584074&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[   Windows ]-------------------------------------------------------------------------------------

  [ Samsung SSD 970 EVO 500GB ]

     :
                                        Samsung SSD 970 EVO 500GB
                                            21.06.2006
                                          10.0.19041.1865
                                       Microsoft
      INF-                                          disk.inf
      INF Section                                       disk_install.NT

     :
                                                   Samsung
                                     http://www.samsung.com/us/computer/solid-state-drives

  [   SATA AHCI ]

     :
                                        Standard SATA AHCI Controller
                                            21.06.2006
                                          10.0.19041.1889
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       msahci_Inst

     :
      IRQ                                               65536
                                                  F7680000-F769FFFF

  [   SATA AHCI ]

     :
                                        Standard SATA AHCI Controller
                                            21.06.2006
                                          10.0.19041.1889
                                       Microsoft
      INF-                                          mshdc.inf
      INF Section                                       msahci_Inst

     :
      IRQ                                               524288
                                                  F7708000-F7708FFF

  [    () ]

     :
                                        Microsoft Storage Spaces Controller
                                            21.06.2006
                                          10.0.19041.2846
                                       Microsoft
      INF-                                          spaceport.inf
      INF Section                                       Spaceport_Install

  [   NVM Express ]

     :
                                        Standard NVM Express Controller
                                            21.06.2006
                                          10.0.19041.2075
                                       Microsoft
      INF-                                          stornvme.inf
      INF Section                                       Stornvme_Inst

     :
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
      IRQ                                               65536
                                                  F7800000-F7803FFF


--------[   ]--------------------------------------------------------------------------------------------

    [ TRIAL VERSION ]                                NTFS      [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]
    Z: ( )                            NTFS         373909      268688      105221    28 %  90AE-ADF5


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - Samsung SSD 970 EVO 500GB (465 ) ]

    #1               MS Reserved                                                      1 MB       16 MB
    #2               EFI System                                                     530 MB       99 MB
    #3               Basic Data       C:                                            629 MB   101853 MB
    #4               MS Recovery                                                 102483 MB      545 MB
    #5               Basic Data       Z: ( )                      103029 MB   373910 MB


--------[ ASPI ]--------------------------------------------------------------------------------------------------------

    02  00  00         NVMe      Samsung SSD 970   EXE7  
    02  07  00  -             stornvme                          


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ Samsung SSD 970 EVO 500GB (S5H7NS0N927229B) ]

      NVMe:
      ID                                          Samsung SSD 970 EVO 500GB
                                           S5H7NS0N927229B
                                                  2B2QEXE7
                                           NVMe v1.2
                                476940 
      PCI Vendor ID                                     144Dh  (Samsung)
      PCI Subsystem Vendor ID                           144Dh  (Samsung)
      IEEE OUI Identifier                               38-25-00  (Samsung)
      Controller ID                                     4
                                                  66304
      Recommended Arbitration Burst Size                2
      Max Data Transfer Size                            9
      Runtime D3 Resume Latency                         200000 us
      Runtime D3 Entry Latency                          8000000 us
      Abort Command Limit                               8
      Asynchronous Event Request Limit                  4
      Firmware Slots                                    3
      Max Error Log Page Entries                        64
      Power States                                      5
      Warning Composite Temperature Threshold           358
      Critical Composite Temperature Threshold          358
      Total NVM Capacity                                476940 
      Min / Max Submission Queue Entry Size             64 / 64 
      Min / Max Completion Queue Entry Size             16 / 16 
      Namespaces                                        1
      Atomic Write Unit Normal                          1024 blocks
      Atomic Write Unit Power Fail                      1 blocks

      NVMe:
      Autonomous Power State Transitions                
      Command Effects Log Page                          
      Compare & Write Fused Operation                    
      Cryptographic Erase                               
      Firmware Activation Without Reset                 
      First Firmware Slot Read Only                     
      Format All Namespaces                             
      Multiple Controllers                              
      Multiple PCIe Ports                               
      Namespace Attribute Changed Event                  
      Reservations                                       
      Save / Select Fields                              
      Secure Erase All Namespaces                        
      SGLs                                               
      SGL Bit Bucket Descriptor                          
      SGL Byte Aligned Contiguous Physical Buffer of Metadata 
      SGL Commands Larger Than Data                      
      SMART Information Per Namespace                   
      SR-IOV Virtual Function                           
      Volatile Write Cache                              

     NVMe:
      Compare                                           
      Dataset Management                                
      Format NVM                                        
      Firmware Commit                                   
      Firmware Image Download                           
      Security Receive                                  
      Security Send                                     
      Write Uncorrectable                               
      Write Zeroes                                      

     :
                                                   Samsung
                                     http://www.samsung.com/us/computer/solid-state-drives
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ Samsung SSD 970 EVO 500GB (S5H7NS0N927229B) ]

    0   Critical Warning                                            0   OK:  
    1   Temperature                                                45   OK:  
    3   Available Spare                                          100 %  OK:  
    4   Available Spare Threshold                                 10 %  OK:  
    5   Percentage Used                                            3 %  OK:  
    32  Data Units Read                                       45.14   OK:  
    48  Data Units Written                                    28.77   OK:  
    64  Host Read Commands                                  779184872   OK:  
    80  Host Write Commands                                 543123962   OK:  
    96  Controller Busy Time                                  2717   OK:  
    112  Power Cycles                                             1659   OK:  
    128  Power-On Hours                                           5566   OK:  
    144  Unsafe Shutdowns                                          231   OK:  
    160  Media Errors                                                0   OK:  
    176  Error Information Log Entries                            3839   OK:  
    192  Warning Composite Temperature Time                       0   OK:  
    196  Critical Composite Temperature Time                      0   OK:  
    200  Temperature Sensor 1                                     45 C  OK:  
    202  Temperature Sensor 2                                     56 C  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [ Realtek Gaming GbE Family Controller ]

      :
                                          Realtek Gaming GbE Family Controller
                                           Ethernet
                                         18-C0-4D-44-F2-23
                                              Ethernet
                                      1000 Mbps
      MTU                                               1500 
      DHCP-                               19.07.2023 21:59:56
      DHCP-                               19.07.2023 23:59:56
                                            7732724362 (7374.5 )
                                          239804607 (228.7 )

      :
      IP /                                  [ TRIAL VERSION ]
                                                    [ TRIAL VERSION ]
      DHCP                                              [ TRIAL VERSION ]
      DNS                                               [ TRIAL VERSION ]
      DNS                                               [ TRIAL VERSION ]

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter (PHY: Realtek RTL8111)        PCI


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        https://www.ya.ru/?win=602&clid=2413707-14
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       %11%\blank.htm
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.0.1  25   192.168.0.105 (Realtek Gaming GbE Family Controller)
                127.0.0.0        255.0.0.0        127.0.0.1  331  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  331  [ TRIAL VERSION ]
          127.255.255.255  255.255.255.255        127.0.0.1  331  127.0.0.1 (Software Loopback Interface 1)
              192.168.0.0    255.255.255.0    192.168.0.105  281  192.168.0.105 (Realtek Gaming GbE Family Controller)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  281  [ TRIAL VERSION ]
            192.168.0.255  255.255.255.255    192.168.0.105  281  192.168.0.105 (Realtek Gaming GbE Family Controller)
                224.0.0.0        240.0.0.0        127.0.0.1  331  127.0.0.1 (Software Loopback Interface 1)
          [ TRIAL VERSION ]  [ TRIAL VERSION ]  [ TRIAL VERSION ]  281  [ TRIAL VERSION ]
          255.255.255.255  255.255.255.255        127.0.0.1  331  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.0.105  281  192.168.0.105 (Realtek Gaming GbE Family Controller)


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              10.00.19041.0746  Final Retail                      76800  05.05.2023 15:21:43
    bdaplgin.ax                               10.00.19041.0001  Final Retail                         76288  07.12.2019 12:10:04
    d2d1.dll                                  10.00.19041.0546  Final Retail  Russian                     5371544  05.05.2023 15:21:06
    d3d10.dll                                 10.00.19041.0001  Final Retail  English                     1041920  07.12.2019 12:09:28
    d3d10_1.dll                               10.00.19041.0001  Final Retail  English                      151040  07.12.2019 12:09:28
    d3d10_1core.dll                           10.00.19041.0001  Final Retail  English                       34304  07.12.2019 12:09:28
    d3d10core.dll                             10.00.19041.0001  Final Retail  English                       33792  07.12.2019 12:09:28
    d3d10level9.dll                           10.00.19041.0001  Final Retail  English                      325344  07.12.2019 12:09:18
    d3d10warp.dll                             10.00.19041.2788  Final Retail  English                     5999704  05.05.2023 15:21:06
    d3d11.dll                                 10.00.19041.2913  Final Retail  English                     1964280  05.05.2023 15:21:06
    d3d12.dll                                 10.00.19041.1266  Final Retail  English                       83128  05.05.2023 15:21:10
    d3d8.dll                                  10.00.19041.0001  Final Retail                     714752  07.12.2019 12:09:26
    d3d8thk.dll                               10.00.19041.2788  Final Retail                      12800  05.05.2023 15:21:13
    d3d9.dll                                  10.00.19041.2788  Final Retail                    1619704  05.05.2023 15:21:13
    d3dim.dll                                 10.00.19041.0001  Final Retail                     318976  07.12.2019 12:09:26
    d3dim700.dll                              10.00.19041.0001  Final Retail                     388096  07.12.2019 12:09:26
    d3dramp.dll                               10.00.19041.0001  Final Retail                     595456  07.12.2019 12:09:26
    d3dxof.dll                                10.00.19041.0001  Final Retail                      56832  07.12.2019 12:09:26
    ddraw.dll                                 10.00.19041.0001  Final Retail                        527360  07.12.2019 12:09:26
    ddrawex.dll                               10.00.19041.0001  Final Retail                      41472  07.12.2019 12:09:26
    devenum.dll                               10.00.19041.0746  Final Retail                         93960  05.05.2023 15:21:43
    dinput.dll                                10.00.19041.0001  Final Retail                        135680  07.12.2019 12:09:57
    dinput8.dll                               10.00.19041.0001  Final Retail                        171008  07.12.2019 12:09:57
    dmband.dll                                10.00.19041.2728  Final Retail                      33792  05.05.2023 15:21:39
    dmcompos.dll                              10.00.19041.2728  Final Retail                      74240  05.05.2023 15:21:39
    dmime.dll                                 10.00.19041.2728  Final Retail                     198656  05.05.2023 15:21:39
    dmloader.dll                              10.00.19041.2728  Final Retail                      41472  05.05.2023 15:21:38
    dmscript.dll                              10.00.19041.2728  Final Retail                      97280  05.05.2023 15:21:39
    dmstyle.dll                               10.00.19041.2728  Final Retail                     117760  05.05.2023 15:21:39
    dmsynth.dll                               10.00.19041.2728  Final Retail                     112640  05.05.2023 15:21:39
    dmusic.dll                                10.00.19041.2728  Final Retail                        109568  05.05.2023 15:21:39
    dplaysvr.exe                              10.00.19041.0001  Final Retail                         20480  18.07.2023 22:05:29
    dplayx.dll                                10.00.19041.0001  Final Retail                     215552  18.07.2023 22:05:29
    dpmodemx.dll                              10.00.19041.0001  Final Retail                         23552  18.07.2023 22:05:29
    dpnaddr.dll                               10.00.19041.0001  Final Retail                       5120  18.07.2023 22:05:28
    dpnathlp.dll                              10.00.19041.0001  Final Retail  English                       60928  18.07.2023 22:05:30
    dpnet.dll                                 10.00.19041.0001  Final Retail                        383488  18.07.2023 22:05:28
    dpnhpast.dll                              10.00.19041.0001  Final Retail                       8192  18.07.2023 22:05:28
    dpnhupnp.dll                              10.00.19041.0001  Final Retail                       8192  18.07.2023 22:05:28
    dpnlobby.dll                              10.00.19041.0001  Final Retail                       5120  18.07.2023 22:05:28
    dpnsvr.exe                                10.00.19041.0001  Final Retail                         22528  18.07.2023 22:05:28
    dpwsockx.dll                              10.00.19041.0001  Final Retail                         45568  18.07.2023 22:05:29
    dsdmo.dll                                 10.00.19041.2728  Final Retail                     183808  05.05.2023 15:20:57
    dsound.dll                                10.00.19041.2728  Final Retail                        493056  05.05.2023 15:20:57
    dswave.dll                                10.00.19041.2728  Final Retail                      23040  05.05.2023 15:21:39
    dwrite.dll                                10.00.19041.1566  Final Retail  Russian                     2104320  05.05.2023 15:21:06
    dxdiagn.dll                               10.00.19041.2075  Final Retail                        459264  05.05.2023 15:21:39
    dxgi.dll                                  10.00.19041.2311  Final Retail  English                      785056  05.05.2023 15:21:06
    dxmasf.dll                                12.00.19041.1266  Final Retail                       5632  05.05.2023 15:22:19
    dxtmsft.dll                               11.00.19041.0746  Final Retail  English                      396800  05.05.2023 15:21:40
    dxtrans.dll                               11.00.19041.0746  Final Retail  English                      267776  05.05.2023 15:21:40
    dxva2.dll                                 10.00.19041.0001  Final Retail  English                      106384  07.12.2019 12:09:18
    encapi.dll                                10.00.19041.0001  Final Retail                      20992  07.12.2019 12:10:04
    gcdef.dll                                 10.00.19041.0001  Final Retail                        124416  07.12.2019 12:09:57
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  07.12.2019 12:10:00
    ir41_32.ax                                10.00.19041.0001  Final Retail                       9216  07.12.2019 12:10:00
    ir41_qc.dll                               10.00.19041.0001  Final Retail                       8704  07.12.2019 12:10:00
    ir41_qcx.dll                              10.00.19041.0001  Final Retail                       8704  07.12.2019 12:10:00
    ir50_32.dll                               10.00.19041.0001  Final Retail                       9216  07.12.2019 12:10:00
    ir50_qc.dll                               10.00.19041.0001  Final Retail                       9216  07.12.2019 12:10:00
    ir50_qcx.dll                              10.00.19041.0001  Final Retail                       9216  07.12.2019 12:10:00
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  07.12.2019 12:10:00
    joy.cpl                                   10.00.19041.0001  Final Retail                         90624  07.12.2019 12:09:57
    ksproxy.ax                                10.00.19041.0746  Final Retail                        234496  05.05.2023 15:21:43
    kstvtune.ax                               10.00.19041.0001  Final Retail                         89600  07.12.2019 12:10:04
    ksuser.dll                                10.00.19041.0001  Final Retail                         20328  07.12.2019 12:09:11
    kswdmcap.ax                               10.00.19041.0001  Final Retail                        116224  07.12.2019 12:10:04
    ksxbar.ax                                 10.00.19041.0001  Final Retail                         53248  07.12.2019 12:10:04
    mciqtz32.dll                              10.00.19041.0001  Final Retail                         38400  07.12.2019 12:10:04
    mfc40.dll                                 4.01.0000.6140    Final Retail                        924944  07.12.2019 12:09:13
    mfc42.dll                                 6.06.8063.0000    Beta Retail                        1171456  07.12.2019 12:09:13
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  19.07.2023 21:53:50
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  19.07.2023 21:53:50
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  19.07.2023 21:53:50
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  19.07.2023 21:53:48
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  19.07.2023 21:53:48
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  19.07.2023 21:53:48
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  19.07.2023 21:53:49
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  19.07.2023 21:53:49
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  19.07.2023 21:53:49
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  19.07.2023 21:53:49
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  19.07.2023 21:53:49
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  19.07.2023 21:53:50
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  19.07.2023 21:53:51
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  19.07.2023 21:53:51
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  19.07.2023 21:53:51
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  19.07.2023 21:53:51
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  19.07.2023 21:53:51
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  19.07.2023 21:53:50
    mpeg2data.ax                              10.00.19041.0001  Final Retail                         75776  07.12.2019 12:10:04
    mpg2splt.ax                               10.00.19041.0329  Final Retail                     204800  05.05.2023 15:21:44
    msdmo.dll                                 10.00.19041.0001  Final Retail                      28896  07.12.2019 12:09:11
    msdvbnp.ax                                10.00.19041.0001  Final Retail                         66560  07.12.2019 12:10:04
    msvidctl.dll                              6.05.19041.0746   Final Retail                       2205184  05.05.2023 15:21:44
    msyuv.dll                                 10.00.19041.0001  Final Retail                      23552  07.12.2019 12:10:04
    pid.dll                                   10.00.19041.0001  Final Retail                      38400  07.12.2019 12:09:57
    psisdecd.dll                              10.00.19041.0746  Final Retail                        484352  05.05.2023 15:21:44
    psisrndr.ax                               10.00.19041.0001  Final Retail                         80384  07.12.2019 12:10:04
    qasf.dll                                  12.00.19041.0001  Final Retail                     127488  07.12.2019 12:10:00
    qcap.dll                                  10.00.19041.0001  Final Retail                        211968  07.12.2019 12:10:04
    qdv.dll                                   10.00.19041.0001  Final Retail                        291328  07.12.2019 12:10:04
    qdvd.dll                                  10.00.19041.0746  Final Retail                        550400  05.05.2023 15:21:43
    qedit.dll                                 10.00.19041.0746  Final Retail                        557056  05.05.2023 15:21:44
    qedwipes.dll                              10.00.19041.0001  Final Retail                       2560  07.12.2019 12:10:05
    quartz.dll                                10.00.19041.0746  Final Retail                       1470976  05.05.2023 15:21:43
    vbisurf.ax                                10.00.19041.0001  Final Retail                      37888  07.12.2019 12:10:04
    vfwwdm32.dll                              10.00.19041.0001  Final Retail                         56832  07.12.2019 12:10:04
    wsock32.dll                               10.00.19041.0001  Final Retail                         16384  07.12.2019 12:09:15


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       nvldumd.dll
                                      NVIDIA GeForce RTX 3060

     Direct3D:
      /                         12288  / 11237 
                                8, 16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x, CSAA 8xQ
                               1 x 1
                              16384 x 16384
                              5.1
        DirectX                      DirectX v11.1

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      Directional Lights                                
      DirectX Texture Compression                        
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                              
      Dynamic Textures                                  
      Edge Anti-Aliasing                                
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Map On Default Buffers                            
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Lights                                      
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Runtime Shader Linking                            
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Spot Lights                                       
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Tiled Resources                                   
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                    
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      3x11                                              
      3x16                                              
      AI44                                              
      AIP8                                              
      ATOC                                              
      AV12                                              
      AYUV                                              
      NV12                                              
      NV24                                              
      NVDB                                              
      NVDP                                              
      NVMD                                              
      P010                                              
      PLFF                                              
      SSAA                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ Headset Earphone (CONEXANT USB AUDIO) ]

     DirectSound:
                                      Headset Earphone (CONEXANT USB AUDIO)
                                          {0.0.0.00000000}.{e9d94612-0ae7-4632-8a58-24b5e61be9d1}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ MSI G273 (NVIDIA High Definition Audio) ]

     DirectSound:
                                      MSI G273 (NVIDIA High Definition Audio)
                                          {0.0.0.00000000}.{3948da6c-4cad-4f53-b29e-b274d5b3b893}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Realtek(R) Audio) ]

     DirectSound:
                                       (Realtek(R) Audio)
                                          {0.0.0.00000000}.{d6935c06-857d-4a23-96a7-a59b38490afc}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (HyperX Quadcast) ]

     DirectSound:
                                       (HyperX Quadcast)
                                          {0.0.0.00000000}.{da4f7b2b-a8ca-4183-9fd9-2bfd823f3c45}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ Realtek Digital Output (Realtek(R) Audio) ]

     DirectSound:
                                      Realtek Digital Output (Realtek(R) Audio)
                                          {0.0.0.00000000}.{f3faf2d3-1842-4239-a61d-29481b6399bc}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD K17 - Cryptographic Coprocessor PSPCPP ]

     :
                                      AMD K17 - Cryptographic Coprocessor PSPCPP
                                                 PCI Express 3.0 x16
       /  /                        8 / 0 / 2
      ID                                      1022-1456
                               1022-1456
                                         1080 (En/decryption Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 0 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 0
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1460
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 1 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 1
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1461
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 2 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 2
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1462
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 3 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 3
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1463
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 4 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 4
                                                 PCI
       /  /                        0 / 24 / 4
      ID                                      1022-1464
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 5 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 5
                                                 PCI
       /  /                        0 / 24 / 5
      ID                                      1022-1465
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 6 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 6
                                                 PCI
       /  /                        0 / 24 / 6
      ID                                      1022-1466
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Data Fabric: Device 18h; Function 7 ]

     :
                                      AMD K17 - Data Fabric: Device 18h; Function 7
                                                 PCI
       /  /                        0 / 24 / 7
      ID                                      1022-1467
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - High Definition Audio Controller ]

     :
                                      AMD K17 - High Definition Audio Controller
                                                 PCI Express 3.0 x16
       /  /                        9 / 0 / 3
      ID                                      1022-1457
                               1458-A182
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C ]

     :
                                      AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C
                                                 PCI
       /  /                        0 / 7 / 1
      ID                                      1022-1454
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C ]

     :
                                      AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C
                                                 PCI
       /  /                        0 / 8 / 1
      ID                                      1022-1454
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - IOMMU ]

     :
                                      AMD K17 - IOMMU
                                                 PCI
       /  /                        0 / 0 / 2
      ID                                      1022-1451
                               1022-1451
                                         0806 (Base System Peripheral)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Function ]

     :
                                      AMD K17 - PCIe Dummy Function
                                                 PCI Express 3.0 x16
       /  /                        8 / 0 / 0
      ID                                      1022-145A
                               1022-145A
                                         1300
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Function ]

     :
                                      AMD K17 - PCIe Dummy Function
                                                 PCI Express 3.0 x16
       /  /                        9 / 0 / 0
      ID                                      1022-1455
                               1022-1455
                                         1300
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 1 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 3 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 4 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 7 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe Dummy Host Bridge ]

     :
                                      AMD K17 - PCIe Dummy Host Bridge
                                                 PCI
       /  /                        0 / 8 / 0
      ID                                      1022-1452
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe GPP Bridge [7:0] ]

     :
                                      AMD K17 - PCIe GPP Bridge [7:0]
                                                 PCI
       /  /                        0 / 1 / 1
      ID                                      1022-1453
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe GPP Bridge [7:0] ]

     :
                                      AMD K17 - PCIe GPP Bridge [7:0]
                                                 PCI
       /  /                        0 / 1 / 3
      ID                                      1022-1453
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - PCIe GPP Bridge [7:0] ]

     :
                                      AMD K17 - PCIe GPP Bridge [7:0]
                                                 PCI
       /  /                        0 / 3 / 1
      ID                                      1022-1453
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Reserved ]

     :
                                      AMD K17 - Reserved
                                                 PCI Express 3.0 x16
       /  /                        8 / 0 / 3
      ID                                      1022-145F
                               1458-5007
                                         0C03 (USB3 xHCI Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 - Root Complex ]

     :
                                      AMD K17 - Root Complex
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      1022-1450
                               1022-1450
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 FCH - LPC Bridge ]

     :
                                      AMD K17 FCH - LPC Bridge
                                                 PCI
       /  /                        0 / 20 / 3
      ID                                      1022-790E
                               1458-5001
                                         0601 (PCI/ISA Bridge)
                                                  51
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ AMD K17 FCH - SATA AHCI Controller ]

     :
                                      AMD K17 FCH - SATA AHCI Controller
                                                 PCI Express 3.0 x16
       /  /                        9 / 0 / 2
      ID                                      1022-7901
                               1458-B002
                                         0106 (SATA Controller)
                                                  51
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K17 FCH - SMBus and ACPI Controller ]

     :
                                      AMD K17 FCH - SMBus and ACPI Controller
                                                 PCI
       /  /                        0 / 20 / 0
      ID                                      1022-790B
                               1458-5001
                                         0C05 (SMBus Controller)
                                                  59
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ NVIDIA GeForce RTX 3060 [10DE-2504] [NoDB] ]

     :
                                      NVIDIA GeForce RTX 3060 [10DE-2504] [NoDB]
                                                 PCI Express 3.0 x16
       /  /                        7 / 0 / 0
      ID                                      10DE-2504
                               1458-4074
                                         0300 (VGA Display Controller)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter ]

     :
                                      Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter
                                                 PCI Express 2.0 x1
       /  /                        4 / 0 / 0
      ID                                      10EC-8168
                               1458-E000
                                         0200 (Ethernet Controller)
                                                  16
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [  High Definition Audio (Microsoft) [10DE-228E] [NoDB] ]

     :
                                       High Definition Audio (Microsoft) [10DE-228E] [NoDB]
                                                 PCI Express 3.0 x16
       /  /                        7 / 0 / 1
      ID                                      10DE-228E
                               1458-4074
                                         0403 (High Definition Audio)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [  PCI Express Downstream Switch [1022-43C7] [NoDB] ]

     :
                                       PCI Express Downstream Switch [1022-43C7] [NoDB]
                                                 PCI
       /  /                        3 / 0 / 0
      ID                                      1022-43C7
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [  PCI Express Downstream Switch [1022-43C7] [NoDB] ]

     :
                                       PCI Express Downstream Switch [1022-43C7] [NoDB]
                                                 PCI
       /  /                        3 / 1 / 0
      ID                                      1022-43C7
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [  PCI Express Downstream Switch [1022-43C7] [NoDB] ]

     :
                                       PCI Express Downstream Switch [1022-43C7] [NoDB]
                                                 PCI
       /  /                        3 / 4 / 0
      ID                                      1022-43C7
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [  PCI Express Upstream Switch [1022-43C6] [NoDB] ]

     :
                                       PCI Express Upstream Switch [1022-43C6] [NoDB]
                                                 PCI
       /  /                        2 / 0 / 2
      ID                                      1022-43C6
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [  - AMD USB 3.10  1.10 () [1022-43D5] [NoDB] ]

     :
                                       - AMD USB 3.10  1.10 () [1022-43D5] [NoDB]
                                                 PCI Express 3.0 x4
       /  /                        2 / 0 / 0
      ID                                      1022-43D5
                               1B21-1142
                                         0C03 (USB3 xHCI Controller)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [   NVM Express [144D-A808] [NoDB] ]

     :
                                        NVM Express [144D-A808] [NoDB]
                                                 PCI Express 3.0 x4
       /  /                        1 / 0 / 0
      ID                                      144D-A808
                               144D-A801
                                         0108 (Non-Volatile Memory Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [   SATA AHCI [1022-43C8] [NoDB] ]

     :
                                        SATA AHCI [1022-43C8] [NoDB]
                                                 PCI Express 3.0 x4
       /  /                        2 / 0 / 1
      ID                                      1022-43C8
                               1B21-1062
                                         0106 (SATA Controller)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     


--------[  USB ]----------------------------------------------------------------------------------------------

  [  USB  (CONEXANT USB AUDIO) ]

     :
                                       USB 
      ID                                      0951-16A4
                                         01 / 01 (Audio Control)
                                      00
                                           Conexant
                                                 CONEXANT USB AUDIO
                                           000000000000
        USB                         2.00
                                         Full  (USB 1.1)

  [  USB  (HyperX Quadcast) ]

     :
                                       USB 
      ID                                      0951-16DF
                                         01 / 01 (Audio Control)
                                      00
                                           Kingston
                                                 HyperX Quadcast
                                           4110
        USB                         1.10
                                         Full  (USB 1.1)

  [  USB  (HyperX Alloy Origins Core) ]

     :
                                       USB 
      ID                                      0951-16E6
                                         03 / 01 (Human Interface Device)
                                      01
                                           Kingston
                                                 HyperX Alloy Origins Core
        USB                         2.00
                                         Full  (USB 1.1)

  [  USB  (2.4G Wireless Receiver) ]

     :
                                       USB 
      ID                                      25A7-FA7C
                                         03 / 01 (Human Interface Device)
                                      02
                                           Compx
                                                 2.4G Wireless Receiver
        USB                         2.00
                                         Full  (USB 1.1)


--------[  ]------------------------------------------------------------------------------------------------

    Battle.net                         Registry\User\Run        C:\Program Files (x86)\Battle.net\Battle.net.exe --autostarted
    Discord                            Registry\User\Run        C:\Users\\AppData\Local\Discord\Update.exe --processStart Discord.exe
    FACEIT                             Registry\User\Run        C:\Users\\AppData\Local\FACEIT\update.exe --processStart "FACEIT.exe"
    GameCenter                         Registry\User\Run        C:\Users\\AppData\Local\GameCenter\GameCenter.exe -autostart
    GoogleChromeAutoLaunch_C08B38C952798844734D6E962BC1D20B  Registry\User\Run        C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5
    Lesta Game Center                  Registry\User\Run        Z:\Lesta\GameCenter\lgc.exe --background
    Lightshot                          Registry\Common\Run      C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe 
    OneDrive                           Registry\User\Run        C:\Users\\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background
    RtkAudUService                     Registry\Common\Run      C:\WINDOWS\System32\RtkAudUService64.exe -background
    SecurityHealth                     Registry\Common\Run      %windir%\system32\SecurityHealthSystray.exe 
    Steam                              Registry\User\Run        Z:\Steam\steam.exe -silent


--------[   ]-------------------------------------------------------------------------------------

    4K Video Downloader                                                                    4.24.1.5352    {76279A4A-4172-4200-9C40-75E61464240B}        Open Media LLC                  2023-04-12
    Addapp [ TRIAL VERSION ]                                                                    2022.3    RetailA [ TRIAL VERSION ]                     Yandex                          2023-04-10
    AIDA64 [ TRIAL VERSION ]                                                                      5.70    AIDA64  [ TRIAL VERSION ]                     FinalWire Ltd.                  2023-07-19
    ARDOR  [ TRIAL VERSION ]                                                                       1.0    {149207 [ TRIAL VERSION ]                     ARDOR GAMING                    2023-04-04
    ArtMon [ TRIAL VERSION ]                                                                    8.16.0    ArtMone [ TRIAL VERSION ]                     System SoftLab                  2023-05-30
    Atomic [ TRIAL VERSION ]                                                                      1.10    gcgame_ [ TRIAL VERSION ]                     CIS: GRN + VK Play, World: Focus Entertainment            
    Battle [ TRIAL VERSION ]                                                                              Battle. [ TRIAL VERSION ]                     Blizzard Entertainment                    
    Battle [ TRIAL VERSION ]                                                               13.0.2.1988    {B0FDA0 [ TRIAL VERSION ]                     Battlestate Games               2023-07-11
    Call o [ TRIAL VERSION ]                                                                              Call of [ TRIAL VERSION ]                     Blizzard Entertainment                    
    Contro [ TRIAL VERSION ]                                                                              Steam A [ TRIAL VERSION ]                     Remedy Entertainment                      
    Crysta [ TRIAL VERSION ]                                                                     9.1.1    Crystal [ TRIAL VERSION ]                     Crystal Dew World               2023-07-13
    Discord                                                                                   1.0.9011    Discord                                       Discord Inc.                    2023-47-04
    Dota 2                                                                                                Steam App 570                                 Valve                                     
    Escape from Tarkov                                                                  0.13.1.1.24742    EscapeFromTarkov                              Battlestate Games                         
    FACEIT Anti-Cheat                                                                              2.1    {1419E44C-0EF4-4822-9194-9F1A4D43973D}_is1    FACEIT LTD                      2023-04-10
    FACEIT                                                                                     1.31.13    FACEIT                                        FACEIT Ltd.                     2023-04-10
    GameCheck_RU                                                                                          LGC-3882158293                                Lesta Games                     2023-07-11
    Geeks3D FurMark 1.21.0.0                                                                              {2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1    Geeks3D                         2023-07-13
    Google Chrome                                                                       114.0.5735.199    Google Chrome                                 Google LLC                      2023-06-29
    Just Cause 2                                                                                          Steam App 8190                                Avalanche Studios                         
    Just Cause 3                                                                                          Steam App 225540                              Avalanche Studios                         
    KorbenTeam Modpack 1.21.0.0,  2                                                            2    {58D66D7F-D9F6-4490-8CC2-EA8E72B51BAC}_is1                                    2023-07-07
    Lesta Game Center                                                                       23.2.1.243    Lesta Game Center                             Lesta Games                               
    Lightshot-5.5.0.7                                                                          5.5.0.7    {30A5B3C9-2084-4063-A32A-628A98DE512B}_is1    Skillbrains                     2023-04-04
    Microsoft Access MUI (Russian) 2016 [ ()]                              16.0.4266.1001    {90160000-0015-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft DCF MUI (Russian) 2016 [ ()]                                 16.0.4266.1001    {90160000-0090-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Edge Update                                                                   1.3.177.11    Microsoft Edge Update                                                                   
    Microsoft Edge                                                                       114.0.1823.86    Microsoft Edge                                            2023-07-18
    Microsoft Excel MUI (Russian) 2016 [ ()]                               16.0.4266.1001    {90160000-0016-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Groove MUI (Russian) 2016 [ ()]                              16.0.4266.1001    {90160000-00BA-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft InfoPath MUI (Russian) 2016 [ ()]                            16.0.4266.1001    {90160000-0044-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office 32-bit Components 2016                                             16.0.4266.1001    {90160000-00C1-0000-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Korrekturhilfen 2016  Deutsch [ ()]               16.0.4266.1001    {90160000-001F-0407-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office OSM MUI (Russian) 2016 [ ()]                          16.0.4266.1001    {90160000-00E1-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office OSM UX MUI (Russian) 2016 [ ()]                       16.0.4266.1001    {90160000-00E2-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Professional Plus 2016                                             16.0.4266.1001    {90160000-0011-0000-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Proofing (Russian) 2016 [ ()]                         16.0.4266.1001    {90160000-002C-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Proofing Tools 2016 - English                                      16.0.4266.1001    {90160000-001F-0409-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Shared 32-bit MUI (Russian) 2016 [ ()]                16.0.4266.1001    {90160000-00C1-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office Shared MUI (Russian) 2016 [ ()]                       16.0.4266.1001    {90160000-006E-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Office   2016                                         16.0.4266.1001    Office16.PROPLUS                              Microsoft Corporation                     
    Microsoft OneDrive                                                                23.132.0625.0001    OneDriveSetup.exe                             Microsoft Corporation                     
    Microsoft OneNote MUI (Russian) 2016 [ ()]                             16.0.4266.1001    {90160000-00A1-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Outlook MUI (Russian) 2016 [ ()]                             16.0.4266.1001    {90160000-001A-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft PowerPoint MUI (Russian) 2016 [ ()]                          16.0.4266.1001    {90160000-0018-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Publisher MUI (Russian) 2016 [ ()]                           16.0.4266.1001    {90160000-0019-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Skype for Business MUI (Russian) 2016 [ ()]                  16.0.4266.1001    {90160000-012B-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    Microsoft Update Health Tools                                                             3.72.0.0    {BB052C53-34CB-42DE-AF41-66FDFCEEC868}        Microsoft Corporation           2023-05-11
    Microsoft Visual C++ 2005 Redistributable                                                8.0.56336    {7299052b-02a4-4627-81f2-1818da5d550d}        Microsoft Corporation           2023-06-18
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161                      9.0.30729.6161    {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}        Microsoft Corporation           2023-07-14
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161    {9BE518E6-ECC6-35A9-88E4-87755C07200F}        Microsoft Corporation           2023-07-14
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219                             10.0.40219    {1D8E6291-B0D5-35EC-8441-6616F567A0F7}        Microsoft Corporation           2023-04-05
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219                             10.0.40219    {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}        Microsoft Corporation           2023-04-05
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501                          12.0.30501.0    {050d4fc8-5d48-4b8f-8972-47c82c46020f}        Microsoft Corporation                     
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501                          12.0.30501.0    {f65db027-aff3-4070-886a-0d87064aabb1}        Microsoft Corporation                     
    Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005                           12.0.21005    {929FBD26-9020-399B-9A7A-751D61F0B942}        Microsoft Corporation           2023-04-04
    Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005                              12.0.21005    {A749D8E6-B613-3BE3-8F5F-045C84EBA29B}        Microsoft Corporation           2023-04-04
    Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005                           12.0.21005    {F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}        Microsoft Corporation           2023-04-04
    Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005                              12.0.21005    {13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}        Microsoft Corporation           2023-04-04
    Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.36.32532                   14.36.32532.0    {8bdfe669-9705-4184-9368-db9ce581e0e7}        Microsoft Corporation                     
    Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.36.32532                   14.36.32532.0    {410c0ee1-00bb-41b6-9772-e12c2828b02f}        Microsoft Corporation                     
    Microsoft Visual C++ 2022 X64 Additional Runtime - 14.36.32532                         14.36.32532    {0025DD72-A959-45B5-A0A3-7EFEB15A8050}        Microsoft Corporation           2023-05-17
    Microsoft Visual C++ 2022 X64 Minimum Runtime - 14.36.32532                            14.36.32532    {D5D19E2F-7189-42FE-8103-92CD1FA457C2}        Microsoft Corporation           2023-05-17
    Microsoft Visual C++ 2022 X86 Additional Runtime - 14.36.32532                         14.36.32532    {C2C59CAB-8766-4ABD-A8EF-1151A36C41E5}        Microsoft Corporation           2023-05-17
    Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.36.32532                            14.36.32532    {73F77E4E-5A17-46E5-A5FC-8A061047725F}        Microsoft Corporation           2023-05-17
    Microsoft Word MUI (Russian) 2016 [ ()]                                16.0.4266.1001    {90160000-001B-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
    MSI Afterburner 4.6.5                                                                        4.6.5    Afterburner                                   MSI Co., LTD                              
    NVIDIA Backend [ ()]                                                         39.5.0.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend  NVIDIA Corporation              2023-04-04
    NVIDIA Container [ ()]                                                           1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer  NVIDIA Corporation              2023-04-04
    NVIDIA FrameView SDK 1.3.8513.32290073 [ ()]                         1.3.8513.32290073    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_FrameViewSdk  NVIDIA Corporation              2023-04-04
    NVIDIA GeForce Experience 3.27.0.112 [ ()]                                 3.27.0.112    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience  NVIDIA Corporation              2023-04-04
    NVIDIA GPX Common OSS binaries (POCO, OpenSSL, libprotobuf) [ ()]                 7.1    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GpxCommon.Oss  NVIDIA Corporation              2023-04-04
    NVIDIA Install Application [ ()]                                         2.1002.400.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer  NVIDIA Corporation              2023-07-18
    NVIDIA LocalSystem Container [ ()]                                               1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem  NVIDIA Corporation              2023-04-04
    NVIDIA Message Bus for NvContainer [ ()]                                         1.34    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus  NVIDIA Corporation              2023-04-04
    NVIDIA NetworkService Container [ ()]                                            1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ServiceUser  NVIDIA Corporation              2023-04-04
    NVIDIA NodeJS [ ()]                                                        3.27.0.112    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs  NVIDIA Corporation              2023-04-04
    NVIDIA NVAPI Monitor plugin for NvContainer [ ()]                                 1.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor  NVIDIA Corporation              2023-04-04
    NVIDIA NvModuleTracker [ ()]                                         6.14.25214.24630    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver  NVIDIA Corporation              2023-04-04
    NVIDIA Optimus Update 39.5.0.0 [ ()]                                         39.5.0.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus  NVIDIA Corporation              2023-04-04
    NVIDIA Session Container [ ()]                                                   1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session  NVIDIA Corporation              2023-04-04
    NVIDIA ShadowPlay 3.27.0.112 [ ()]                                         3.27.0.112    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay  NVIDIA Corporation              2023-04-04
    Nvidia Share [ ()]                                                         3.27.0.112    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC    NVIDIA Corporation              2023-04-04
    NVIDIA SHIELD Streaming [ ()]                                            7.1.32193813    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv  NVIDIA Corporation              2023-04-04
    NVIDIA SHIELD Wireless Controller Driver [ ()]                              3.27.0.94    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController  NVIDIA Corporation              2023-04-04
    NVIDIA Telemetry Client [ ()]                                                17.1.7.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry  NVIDIA Corporation              2023-04-04
    NVIDIA TelemetryApi helper for NvContainer [ ()]                                 1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.ContainerTelemetryApiHelper  NVIDIA Corporation              2023-04-04
    NVIDIA Update Core [ ()]                                                     39.5.0.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core  NVIDIA Corporation              2023-04-04
    NVIDIA User Container [ ()]                                                      1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User  NVIDIA Corporation              2023-04-04
    NVIDIA Virtual Audio 4.49.0.0 [ ()]                                          4.49.0.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver  NVIDIA Corporation              2023-04-04
    NVIDIA Virtual Host Controller [ ()]                                         3.05.0.1    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvVHCI  NVIDIA Corporation              2023-04-04
    NVIDIA Watchdog Plugin for NvContainer [ ()]                                     1.37    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog  NVIDIA Corporation              2023-04-04
    NVIDIA  HD 1.3.40.14 [ ()]                                      1.3.40.14    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver  NVIDIA Corporation              2023-07-18
    NVIDIA   536.67 [ ()]                                        536.67    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver  NVIDIA Corporation              2023-07-18
    NVIDIA    PhysX 9.21.0713 [ ()]              9.21.0713    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX  NVIDIA Corporation              2023-04-04
    OBS Studio                                                                                  29.0.2    OBS Studio                                    OBS Project                               
    PUBG: BATTLEGROUNDS                                                                                   Steam App 578080                              KRAFTON, Inc.                             
    Riot Client                                                                                           Riot Game Riot_Client.                        Riot Games, Inc                           
    Rise of the Tomb Raider                                                                               Steam App 391220                              Crystal Dynamics                          
    RivaTuner Statistics Server 7.3.4                                                            7.3.4    RTSS                                          Unwinder                                  
    S.T.A.L.K.E.R.: Shadow of Chernobyl                                                                   Steam App 4500                                GSC Game World                            
    Shadow of the Tomb Raider                                                                             Steam App 750920                              Eidos-Montreal                            
    Soundpad                                                                                              Steam App 629520                              Leppsoft                                  
    Steam                                                                                   2.10.91.91    Steam                                         Valve Corporation                         
    Telegram Desktop                                                                             4.8.3    {53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1    Telegram FZ-LLC                 2023-06-06
    VK Pla [ TRIAL VERSION ]                                                                    4.1714    GameCen [ TRIAL VERSION ]                      ʻ                                  
    War Ro [ TRIAL VERSION ]                                                                      1.38    gcgame_ [ TRIAL VERSION ]                     Astrum Entertainment                      
    Warfac [ TRIAL VERSION ]                                                                     1.540    gcgame_ [ TRIAL VERSION ]                     Astrum Entertainment                      
    WinRAR [ TRIAL VERSION ]                                                                    6.22.0    WinRAR  [ TRIAL VERSION ]                     win.rar GmbH                              
       Microsoft Office 2016   [ ()]    16.0.4266.1001    {90160000-001F-0422-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13
                                                             3.7.9.0    YaPinLancher                                                                      
                                                                                                 LGC-911972347                                 Lesta Games                     2023-07-11
     NVIDIA 39.5.0.0 [ ()]                                             39.5.0.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update  NVIDIA Corporation              2023-04-04
      Microsoft Edge WebView2 Runtime                                     114.0.1823.86    Microsoft EdgeWebView                                     2023-07-18
       Microsoft Office 2016   [ ()]    16.0.4266.1001    {90160000-001F-0419-1000-0000000FF1CE}        Microsoft Corporation           2023-07-13


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 10 Pro
                                       [ TRIAL VERSION ]
      Winlogon Shell                                    explorer.exe
          (UAC)  
      UAC Remote Restrictions                           
                                   
      Windows Update Agent                              10.0.19041.3203 (WinBuild.160101.0800)

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                            
    2023-07    .NET Framework 3.5, 4.8  4.8.1  Windows 10 Version 22H2  x64  (KB5028937)              19.07.2023
         Microsoft Defender Antivirus - KB2267602 ( 1.393.786.0)              19.07.2023


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              10.0.19041.746  


--------[   ]--------------------------------------------------------------------------------------

     :
                                    RTZ 2 ()
                            (UTC+03:00) , -
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   ?
         (ISO 4217)                RUB
                                      123456789,00 ?
                         -123456789,00 ?

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\ᠭ\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              ALEXANDER_PC
    ComSpec                   C:\WINDOWS\system32\cmd.exe
    DriverData                C:\Windows\System32\Drivers\DriverData
    FPS_BROWSER_APP_PROFILE_STRING  Internet Explorer
    FPS_BROWSER_USER_PROFILE_STRING  Default
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\ᠭ
    LOCALAPPDATA              C:\Users\ᠭ\AppData\Local
    LOGONSERVER               \\ALEXANDER_PC
    NUMBER_OF_PROCESSORS      12
    OneDrive                  C:\Users\ᠭ\OneDrive
    OneDriveConsumer          C:\Users\ᠭ\OneDrive
    OS                        Windows_NT
    Path                      C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Users\ᠭ\AppData\Local\Microsoft\WindowsApps
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 23 Model 8 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL           23
    PROCESSOR_REVISION        0802
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Program Files\WindowsPowerShell\Modules;C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\WINDOWS
    TEMP                      C:\Users\8523~1\AppData\Local\Temp
    TMP                       C:\Users\8523~1\AppData\Local\Temp
    USERDOMAIN_ROAMINGPROFILE  ALEXANDER_PC
    USERDOMAIN                ALEXANDER_PC
    USERNAME                  ᠭ
    USERPROFILE               C:\Users\ᠭ
    windir                    C:\WINDOWS


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    CMCDLLNAME32=mapi32.dll
    CMC=1
    MAPIX=1
    MAPIXVER=1.0.0.1
    OLEMessaging=1

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\\AppData\Roaming
    Cache                        C:\Users\\AppData\Local\Microsoft\Windows\INetCache
    CD Burning                   C:\Users\\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\\AppData\Local\Microsoft\Windows\INetCookies
    Desktop                      C:\Users\\Desktop
    Device                       C:\WINDOWS\inf
    Favorites                    C:\Users\\Favorites
    Fonts                        C:\WINDOWS\Fonts
    History                      C:\Users\\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\\AppData\Local
    My Documents                 C:\Users\\Documents
    My Music                     C:\Users\\Music
    My Pictures                  C:\Users\\Pictures
    My Video                     C:\Users\\Videos
    NetHood                      C:\Users\\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\WINDOWS\resources
    SendTo                       C:\Users\\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\WINDOWS\SysWOW64
    System                       C:\WINDOWS\system32
    Temp                         C:\Users\8523~1\AppData\Local\Temp\
    Templates                    C:\Users\\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\WINDOWS


--------[   ]-------------------------------------------------------------------------------------------

                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_UserStateConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_FolderRedirectionConfiguration     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_FolderRedirectionConfiguration     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_UserStateConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_UserStateConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  InvProv     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  InvProv     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_FolderRedirectionConfiguration     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_FolderRedirectionConfiguration     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_OfflineFilesConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv1     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  DMWmiBridgeProv     ROOT\CIMV2\mdm\dmmap   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  MDMSettingsProv     ROOT\CIMV2\mdm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderCimV2     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  InvProv     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderCimV2     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerWmiProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerWmiProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  PowerMeterProvider     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderCimV2     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderCimV2     ROOT\CIMV2\power   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  InvProv     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  UserProfileConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:56                           Microsoft-Windows-WMI           63:  Win32_UserStateConfigurationProvider     ROOT\CIMV2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  MINT     ROOT\PEH   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  AssignedAccess     ROOT\StandardCimv2\embedded   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  AssignedAccess     ROOT\StandardCimv2\embedded   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  NetEventPacketCapture     ROOT\StandardCimv2   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderInterop     ROOT\Interop   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderInterop     ROOT\Interop   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderInterop     ROOT\Interop   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  ProfileAssociationProviderInterop     ROOT\Interop   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  WsmAgent     ROOT\Microsoft\Windows\winrm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  WsmAgent     ROOT\Microsoft\Windows\winrm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  WsmAgent     ROOT\Microsoft\Windows\winrm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:57                           Microsoft-Windows-WMI           63:  WsmAgent     ROOT\Microsoft\Windows\winrm   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  EventTracingManagement     ROOT\Microsoft\Windows\EventTracingManagement   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  DSCCoreProviders     ROOT\Microsoft\Windows\DesiredStateConfiguration   Windows      LocalSystem.    , ,      ,     .  
                       2023-07-18 22:09:58                           Microsoft-Windows-WMI           63:  DSCCoreProviders     ROOT\Microsoft\Windows\DesiredStateConfiguration   Windows      LocalSystem.    , ,      ,     .  
                         2023-07-18 22:10:12                                  Microsoft-Windows-CAPI2         257:        .  ESENT: -1409.  
                       2023-07-18 22:10:40                           Microsoft-Windows-User Profiles Service  1534:      Create   {D63AA156-D534-4BAC-9BF1-55359CF5EC30};   See Tracelogging for error details.       
                       2023-07-18 22:14:47                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : UserLogon(1)  
                       2023-07-19 00:14:47                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 00:45:02                           MsiInstaller                    1004:     "{ADF29D2B-E4E0-4626-97CF-275FB26D06A4}",  "ProductFiles",  "{90160000-0011-0000-1000-0000000FF1CE}".   "D:\Office16\OUTLFLTR.DLL"  .  
                       2023-07-19 00:45:02                           MsiInstaller                    1001:     "ProductFiles"  "{90160000-0011-0000-1000-0000000FF1CE}"    "{A820B15C-F05C-49DD-B05B-E7948CB3AEF2}"  
                       2023-07-19 10:14:58                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 10:14:59                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : NetworkAvailable  
                       2023-07-19 10:15:05                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : NetworkAvailable  
                       2023-07-19 10:15:07                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : UserLogon(1)  
                       2023-07-19 13:59:55                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 13:59:55                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : NetworkAvailable  
                       2023-07-19 14:00:02                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : NetworkAvailable  
                       2023-07-19 14:00:04                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : UserLogon(1)  
                       2023-07-19 16:00:04                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 18:00:04                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 20:00:04                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
                       2023-07-19 22:00:04                                  Software Protection Platform Service  8233:         .  :0x8007007B  AppId: 0ff1ce15-a989-479d-af46-f275c6370663, SkuId: d450596f-894d-49e0-966a-fd39ed4c4c64  : TimerEvent  
      Audit Success   13312      2023-07-18 22:09:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x94     : ????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:47                                  Microsoft-Windows-Security-Auditing  4696:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7      :    : 0x4    : ?     :     : 0x94     : Registry       :    :  S-1-0-0     :  -     :  -    :  0x3e7  
      Audit Success   13312      2023-07-18 22:09:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x1f8     : ??????????????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x20c     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x1f8    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13573      2023-07-18 22:09:47                                  Microsoft-Windows-Security-Auditing  4826:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  -    :  %%1843      : %%1846      : %%1843    : %%1843     VSM: %%1848     :    :  %%1843    :  %%1843     : %%1843      :      : -      : %%1848     : %%1843  
      Audit Success   12288      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0      :    :  0     : -     :  %%1843    :  %%1842     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :  ?      :     : -     : -    :  -        :    :  -     : -    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-0     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\wininit.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-0     :  UMFD-0     :  Font Driver Host    :  0x178c6     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\wininit.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2b0     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2b8     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x2a0    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2f8     : ????????????????-??6??0????0--?0???????????????e??????      : %%1936    :  S-1-16-16384    -: 0x2b0    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x300     : ??????????????e?????????????????????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x2b0    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x244     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x1f8    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x25c     : ??????????????-??6??8????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x1f8    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x264     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2a0     : ??????????????-??6??8????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x1f8    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13568      2023-07-18 22:09:48                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x175fc  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-1     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-1     :  UMFD-1     :  Font Driver Host    :  0x1ebce     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1842     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1faab     :  0x1fac3      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1fac3     :  0x1faab      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1faab    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1fac3    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:09:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:09:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:09:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:09:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:09:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:09:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:10:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:10:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12292      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:10:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:10:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2f8    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:10:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-578    :   Hyper-V    :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-583    :       :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-579    :           :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :   DCOM    :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :        :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :        :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-580    :        :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-581    :          :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:10:30                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :        :  Builtin      :    :  0x580    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   103        2023-07-18 22:11:23                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   13312      2023-07-18 22:11:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x94     : ????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:47                                  Microsoft-Windows-Security-Auditing  4696:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7      :    : 0x4    : ?     :     : 0x94     : Registry       :    :  S-1-0-0     :  -     :  -    :  0x3e7  
      Audit Success   13312      2023-07-18 22:11:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x1e8     : ??????????????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x1f8     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x1e8    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13573      2023-07-18 22:11:47                                  Microsoft-Windows-Security-Auditing  4826:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  -    :  %%1843      : %%1846      : %%1843    : %%1843     VSM: %%1848     :    :  %%1843    :  %%1843     : %%1843      :      : -      : %%1848     : %%1843  
      Audit Success   13312      2023-07-18 22:11:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x238     : ??????????????-??6??8????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x1e8    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:50                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2cc     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x238    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   12288      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0      :    :  0     : -     :  %%1843    :  %%1842     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :  ?      :     : -     : -    :  -        :    :  -     : -    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-0     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x338    :  C:\Windows\System32\wininit.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-0     :  UMFD-0     :  Font Driver Host    :  0x108a9     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x338    :  C:\Windows\System32\wininit.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-1     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x408    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-1     :  UMFD-1     :  Font Driver Host    :  0x12dcb     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x408    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x408    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1842     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x170d1     :  0x170f1      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x408    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x170f1     :  0x170d1      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x408    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x170d1    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x170f1    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13312      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x32c     : ??????????????-??6??8????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x1e8    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x338     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x238    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x344     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x32c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x390     : ????????????????-??6??8????0--?0???????????????e??????      : %%1936    :  S-1-16-16384    -: 0x338    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x398     : ??????????????e?????????????????????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x338    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13568      2023-07-18 22:11:52                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x10543  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-578    :   Hyper-V    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-583    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-579    :           :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :   DCOM    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-580    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-581    :          :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xb68    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-18 22:11:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xb68    :  C:\Windows\System32\svchost.exe  
      Audit Success   12292      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xd60    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-18 22:11:58                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xd60    :  C:\Windows\System32\svchost.exe  
      Audit Success   12292      2023-07-18 22:11:59                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2023-07-18 22:11:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:11:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-18 22:12:18                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin      :    :  0x1230    :  C:\Program Files (x86)\Microsoft\EdgeUpdate\Install\{4DD0D0E8-4E80-4A5D-96AA-94418ED00D0E}\EDGEMITMP_E3C64.tmp\setup.exe  
      Audit Success   12544      2023-07-18 22:12:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:12:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:12:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:12:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:12:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:12:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:12:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:12:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-18 22:12:35                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x13d4    :  C:\$WINDOWS.~BT\Sources\mighost.exe  
      Audit Success   13826      2023-07-18 22:12:37                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x108c    :  C:\Windows\System32\dllhost.exe  
      Audit Success   13826      2023-07-18 22:12:37                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x108c    :  C:\Windows\System32\dllhost.exe  
      Audit Success   12544      2023-07-18 22:13:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:13:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-18 22:13:47                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x8e8    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-18 22:13:47                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x8e8    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-18 22:13:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:13:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13824      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-578    :   Hyper-V    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-583    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-579    :           :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :   DCOM    :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-580    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-581    :          :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   13826      2023-07-18 22:14:16                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :        :  Builtin      :    :  0x658    :  C:\$WINDOWS.~BT\Sources\setupplatform.exe  
      Audit Success   12544      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12290      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13568      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Temp\winre\ExtractedFromWim    : 0x56c      :    : 0x4b0    : C:\Windows\System32\oobe\msoobe.exe     :     : ?     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13824      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:32                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:39                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  ALEXANDER_PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0xd40    :  C:\Windows\System32\svchost.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0     :  0x2b435d      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xd40    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1843     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d     :  0x2b42c0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xd40    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x140c    :  C:\Windows\System32\LogonUI.exe  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13826      2023-07-18 22:14:40                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x8f8    :  C:\Windows\System32\svchost.exe  
      Audit Success   12290      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d      :    :  6968     : 2023-07-18T19:14:40.6781103Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\Users\\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d      :    :  6968     : 2023-07-18T19:14:40.6781103Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:41                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:42                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:42                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:42                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:42                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:43                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b42c0    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:47                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:48                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:49                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:50                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:50                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:50                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:14:50                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:15:09                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13826      2023-07-18 22:15:10                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xb5c    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   13826      2023-07-18 22:15:10                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xb5c    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   12290      2023-07-18 22:15:11                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   13824      2023-07-18 22:15:11                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:11                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:11                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:12                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:12                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:12                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:12                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   12290      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\908816e790c624e2bdf8a917e2af5cf3_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12292      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d7b98b5b5c6f5eec    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\3f1f0147998660a62af6b3eaa096be89_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-18 22:15:26                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  2400     : 2023-07-18T19:14:31.4767816Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12290      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:27                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:15:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:20                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:16:21                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-18 22:16:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:16:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:16:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:16:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:16:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:16:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:16:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:16:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:16:27                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      ,       .  
      Audit Success   13824      2023-07-18 22:16:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:36                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:16:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:40                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      ,       .  
      Audit Success   13824      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:44                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:24:45                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1bf4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-18 22:25:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:25:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:25:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-18 22:25:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:25:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-18 22:25:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:25:58                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 22:26:26                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      ,       .  
      Audit Success   13824      2023-07-18 22:26:26                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0xbe8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:26:26                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0xbe8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:26:26                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0xbe8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:26:26                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0xbe8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-18 22:26:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:26:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:27:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:27:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:27:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   12544      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:27:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   12290      2023-07-18 22:27:21                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   13824      2023-07-18 22:27:22                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2023-07-18 22:29:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:29:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3b0c    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3b0c    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3b0c    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:29:41                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3b0c    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-18 22:31:16                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 22:31:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:20                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:21                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:22                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-18 22:31:43                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:45:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 22:50:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:50:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 22:50:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 22:50:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 22:50:10                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:50:10                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:50:10                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 22:50:34                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x1dac    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-18 23:00:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 23:05:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:05:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:11:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 23:13:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:13:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:15:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 23:23:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:23:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 23:30:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 23:33:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:33:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 23:40:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:40:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:41:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-18 23:45:29                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-18 23:49:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:49:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-18 23:57:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-18 23:57:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 00:00:30                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-19 00:05:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:05:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:13:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:13:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:14:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 00:14:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:14:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 00:14:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:15:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:15:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:15:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:15:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:19:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:19:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:29:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:29:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:40:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:40:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:45:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:45:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:45:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:45:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:47:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:47:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 00:53:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 00:53:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 01:00:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 01:00:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 01:09:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 01:09:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 01:09:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 01:09:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 01:09:23                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-19 01:09:23                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   13824      2023-07-19 01:09:23                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,       .  
      Audit Success   12544      2023-07-19 01:09:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 01:09:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12290      2023-07-19 01:09:25                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x2b435d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12544      2023-07-19 01:09:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x390    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 01:09:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12545      2023-07-19 01:10:03                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x2b435d      ,   .  ,  ,  .        .  
      Audit Success   103        2023-07-19 01:10:04                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   13824      2023-07-19 01:10:04                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0xd40    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 01:10:04                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0xd40    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 01:10:04                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0xd40    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 01:10:04                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0xd40    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 01:10:04                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0xd40    :  C:\Windows\System32\svchost.exe  
      Audit Success   13312      2023-07-19 10:14:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x94     : ????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:47                                  Microsoft-Windows-Security-Auditing  4696:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7      :    : 0x4    : ?     :     : 0x94     : Registry       :    :  S-1-0-0     :  -     :  -    :  0x3e7  
      Audit Success   13312      2023-07-19 10:14:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x210     : ??????????????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13573      2023-07-19 10:14:47                                  Microsoft-Windows-Security-Auditing  4826:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  -    :  %%1843      : %%1846      : %%1843    : %%1843     VSM: %%1848     :    :  %%1843    :  %%1843     : %%1843      :      : -      : %%1848     : %%1843  
      Audit Success   13312      2023-07-19 10:14:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x224     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:48                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x25c     : ??????????????-??6??0????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:50                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2f4     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x388     : ??????????????-??6??0????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x38c     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:52                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x398     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x388    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:53                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x1b8     : ????????????????-??6??8????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x388    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:53                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x30c     : ???????????????-??6??8????0--?0??????????????????????4      : %%1936    :  S-1-16-16384    -: 0x1b8    -: ??????????????????????4     : ????0--?0??????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:53                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x32c     : ?????????????????e???????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x1b8    -: ??????????????????????4     : ????0--?0??????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   12288      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0      :    :  0     : -     :  %%1843    :  %%1842     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :  ?      :     : -     : -    :  -        :    :  -     : -    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-0     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x38c    :  C:\Windows\System32\wininit.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-1     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1b8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-0     :  UMFD-0     :  Font Driver Host    :  0x124d7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x38c    :  C:\Windows\System32\wininit.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-1     :  UMFD-1     :  Font Driver Host    :  0x124db     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1b8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1842     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1880f     :  0x1883f      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1883f     :  0x1880f      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1880f    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1883f    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13312      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x25c     : ????????????????-??6??c????0--?0???????????????e??????      : %%1936    :  S-1-16-16384    -: 0x38c    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x3e0     : ??????????????e?????????????????????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x38c    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13568      2023-07-19 10:14:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x122be  
      Audit Success   12544      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xacc    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 10:14:58                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xacc    :  C:\Windows\System32\svchost.exe  
      Audit Success   12292      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  ALEXANDER_PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x678    :  C:\Windows\System32\svchost.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55acc     :  0x55c5d      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x678    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1843     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d     :  0x55acc      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x678    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55acc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x518    :  C:\Windows\System32\LogonUI.exe  
      Audit Success   13826      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xeb0    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 10:14:59                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xeb0    :  C:\Windows\System32\svchost.exe  
      Audit Success   12290      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x55c5d     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12292      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x55c5d      :    :  5180     : 2023-07-19T07:15:00.2491115Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\Users\\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x55c5d      :    :  5180     : 2023-07-19T07:15:00.2491115Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12292      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 10:15:00                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x604    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-19 10:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:15:01                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x177c    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 10:15:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:15:02                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x177c    :  C:\Windows\explorer.exe  
      Audit Success   12290      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\908816e790c624e2bdf8a917e2af5cf3_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12292      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d7b98b5b5c6f5eec    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\3f1f0147998660a62af6b3eaa096be89_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  6140     : 2023-07-19T07:15:00.7050950Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13826      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x1d68    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   13826      2023-07-19 10:15:03                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x1d68    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   12290      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x55c5d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:06                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:15:07                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x177c    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 10:15:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:15:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:15:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:15:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:15:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:15:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:15:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:15:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:15:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:16:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 10:16:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:16:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 10:16:23                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x1e80    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 10:16:23                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x1e80    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-19 10:16:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:16:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:17:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,       .  
      Audit Success   13824      2023-07-19 10:17:57                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:17:57                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:17:57                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:17:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 10:18:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:18:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:18:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:18:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13824      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13824      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13824      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13824      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13826      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13826      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   13826      2023-07-19 10:18:10                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin      :    :  0x3520    :  C:\Windows\System32\CompatTelRunner.exe  
      Audit Success   12544      2023-07-19 10:18:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:18:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:20:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:20:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:22:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:22:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 10:22:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:22:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12290      2023-07-19 10:23:00                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x55c5d     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   13824      2023-07-19 10:23:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 10:23:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d    :  %%8100      ,            .  
      Audit Success   12545      2023-07-19 10:23:11                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x55c5d      ,   .  ,  ,  .        .  
      Audit Success   103        2023-07-19 10:23:12                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   13824      2023-07-19 10:23:12                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x678    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 10:23:12                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x678    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 10:23:12                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x678    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 10:23:12                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x678    :  C:\Windows\System32\svchost.exe  
      Audit Success   13824      2023-07-19 10:23:12                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x678    :  C:\Windows\System32\svchost.exe  
      Audit Success   13312      2023-07-19 13:59:44                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x94     : ????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:44                                  Microsoft-Windows-Security-Auditing  4696:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7      :    : 0x4    : ?     :     : 0x94     : Registry       :    :  S-1-0-0     :  -     :  -    :  0x3e7  
      Audit Success   13312      2023-07-19 13:59:44                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x210     : ??????????????-??6?4????0--?0???????      : %%1936    :  S-1-16-16384    -: 0x4    -: ???????     : ????0--?0???????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:44                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x224     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13573      2023-07-19 13:59:44                                  Microsoft-Windows-Security-Auditing  4826:    .    :    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  -    :  %%1843      : %%1846      : %%1843    : %%1843     VSM: %%1848     :    :  %%1843    :  %%1843     : %%1843      :      : -      : %%1848     : %%1843  
      Audit Success   13312      2023-07-19 13:59:45                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x25c     : ??????????????-??6??0????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:47                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x2f4     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x374     : ??????????????-??6??0????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x210    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x37c     : ???????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x25c    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x384     : ??????????????e?????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x374    -: ????????????????????4     : ????0--?0????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x3f8     : ????????????????-??6??4????0--?0????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x374    -: ????????????????????4?     : ????0--?0????????????????????4?      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x23c     : ???????????????-??6??8????0--?0??????????????????????4      : %%1936    :  S-1-16-16384    -: 0x3f8    -: ??????????????????????4     : ????0--?0??????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:49                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x32c     : ?????????????????e???????????????????????????????e??????      : %%1936    :  S-1-16-16384    -: 0x3f8    -: ??????????????????????4     : ????0--?0??????????????????????4      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   12288      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0      :    :  0     : -     :  %%1843    :  %%1842     :  -     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :  ?      :     : -     : -    :  -        :    :  -     : -    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-0     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x37c    :  C:\Windows\System32\wininit.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UMFD-1     :  Font Driver Host   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x3f8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-0     :  UMFD-0     :  Font Driver Host    :  0x1256d     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x37c    :  C:\Windows\System32\wininit.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-96-0-1     :  UMFD-1     :  Font Driver Host    :  0x1257a     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3f8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  DWM-1     :  Window Manager   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x3f8    :  C:\Windows\System32\winlogon.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1842     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1888b     :  0x188bd      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3f8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1842    :  %%1843     :  %%1833     :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x188bd     :  0x1888b      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x3f8    :  C:\Windows\System32\winlogon.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x1888b    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-90-0-1     :  DWM-1     :  Window Manager    :  0x188bd    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13312      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x25c     : ????????????????-??6??c????0--?0???????????????e??????      : %%1936    :  S-1-16-16384    -: 0x37c    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13312      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4688:   .    -:    :  S-1-5-18     :  -     :  -    :  0x3e7     :    :  S-1-0-0     :  -     :  -    :  0x0      :     :  0x3cc     : ??????????????e?????????????????????????????????????4?      : %%1936    :  S-1-16-16384    -: 0x37c    -: ???????????????e??????     : ????0--?0???????????????e??????      "   "   ,          .     1         .   ,             ""    .     2         .   ,            .  ,  ,     ,        ,      .     3           .   ,     ,             .  
      Audit Success   13568      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x12355  
      Audit Success   13826      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xac0    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 13:59:54                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xac0    :  C:\Windows\System32\svchost.exe  
      Audit Success   12292      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12292      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-544    :      :  Builtin      :    :  0xda0    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 13:59:56                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-20     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e4    :    :  S-1-5-32-551    :       :  Builtin      :    :  0xda0    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  ALEXANDER_PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x678    :  C:\Windows\System32\svchost.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5     :  0x6609c      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x678    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  2     : -     :  %%1843    :  %%1843     :  %%1833     :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c     :  0x65ff5      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x678    :  C:\Windows\System32\svchost.exe      :     : ALEXANDER_PC     : 127.0.0.1    :  0        :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x514    :  C:\Windows\System32\LogonUI.exe  
      Audit Success   13826      2023-07-19 13:59:57                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x600    :  C:\Windows\System32\svchost.exe  
      Audit Success   12290      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c      :    :  5692     : 2023-07-19T10:59:57.8811404Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\Users\\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c      :    :  5692     : 2023-07-19T10:59:57.8811404Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12292      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : Microsoft Connected Devices Platform device certificate    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\de7cf8a7901d2ad13e5c67c29e5d1662_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : Microsoft Connected Devices Platform device certificate    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 13:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 13:59:59                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x15dc    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 14:00:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:00:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:00:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12290      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : d7b98b5b5c6f5eec    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\3f1f0147998660a62af6b3eaa096be89_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : d7b98b5b5c6f5eec    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12292      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500         :     : C:\WINDOWS\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys\908816e790c624e2bdf8a917e2af5cf3_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   12292      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  5059:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY      :  0x3e5      :    :  5736     : 2023-07-19T10:59:58.2113290Z     :    : Microsoft Software Key Storage Provider    : ECDSA_P256    : AAD.6452fb29-374a-4651-9812-1763d965ea8f    : %%2500     :   : %%2464    : 0x0  
      Audit Success   12544      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x1ff4    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   13826      2023-07-19 14:00:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x1ff4    :  C:\Windows\System32\SearchIndexer.exe  
      Audit Success   12544      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12290      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12290      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : e7172229-5d5f-665d-6947-8200c5823065    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12292      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP      :  0x3e7      :    :  9188     : 2023-07-19T11:00:02.0598909Z     :    : Microsoft Software Key Storage Provider    : UNKNOWN    : e7172229-5d5f-665d-6947-8200c5823065    : %%2500         :     : C:\ProgramData\Microsoft\Crypto\SystemKeys\0842cf33aee714acca278e1e1394755b_67b963c5-d28b-4660-8399-f64dd6615797   : %%2458    : 0x0  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:00:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 14:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:00:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:00:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:00:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:00:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:00:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:01:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:01:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 14:01:21                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x9c8    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 14:01:21                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x9c8    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-19 14:01:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:01:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12290      2023-07-19 14:01:26                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12544      2023-07-19 14:01:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:01:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:01:57                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:01:57                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:01:57                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:01:58                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:01:58                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:02:04                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 14:02:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:02:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:06:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:06:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:06:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:06:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:07:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:07:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_3296b36dbe4c7fa3.cdf-ms    : 0x119c      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_083d4e330e766c5d.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v4.0.30319_46321ba736a30085.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v4.0.30319_wpf_647a02df72a14032.cdf-ms    : 0x119c      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v4.0.30319_wpf_fonts_0428e0346460ac4c.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v4.0.30319_wpf_en-us_0242687c673a608c.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v4.0.30319_nativeimages_ae465c5139d1dacc.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_d97e7188b51e6116.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v3.0_wpf_f80a7f17f38f3771.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework64_v2.0.50727_443de60f3f6e0828.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_83386eac0379231b.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_c40c7a995ddd757b.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_bc1339ef8efa3c4c.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_fonts_dc62106d96619a3c.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_wpf_en-us_dc5fd125966afabc.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v4.0.30319_nativeimages_7f83bd6ed8241f3a.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v3.0_wpf_b56a2354fbfa0c31.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_framework_v2.0.50727_e9368840261e60ee.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_windowsbase_v4.0_4.0.0.0_31bf3856ad364e35_5764ca98829cd598.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_uiautomationtypes_v4.0_4.0.0.0_31bf3856ad364e35_1f12bec8f88f4450.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_uiautomationprovider_v4.0_4.0.0.0_31bf3856ad364e35_6bb637099f04ee2c.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_uiautomationclientsideproviders_v4.0_4.0.0.0_31bf3856ad364e35_6944991d7b306f0d.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_uiautomationclient_v4.0_4.0.0.0_31bf3856ad364e35_35816ba0d06901c4.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_system.xaml_v4.0_4.0.0.0_b77a5c561934e089_6747aba031bff5b1.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_system.windows.controls.ribbon_v4.0_4.0.0.0_b77a5c561934e089_f0c023acb7bafe74.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_system.core_v4.0_4.0.0.0_b77a5c561934e089_18d3047bb5729e36.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_system_v4.0_4.0.0.0_b77a5c561934e089_4348a29e5981af79.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_presentationframework-systemdata_v4.0_4.0.0.0_b77a5c561934e089_89b90455552a8828.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_microsoft.net_assembly_gac_msil_presentationframework_v4.0_4.0.0.0_31bf3856ad364e35_b57a3b1abb4f9cb2.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86__676bbe2c7241b694.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_41115a5fd4566dab.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_ad470207ad610db1.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_framework_b81ea2cfde84fb19.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_x86_reference_assemblies_microsoft_framework_v3.0_1dfad1527dc1078c.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:32                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_ffd0cbfc813cc4f1.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_f89c5a39d351281a.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_a4ba21b6f468ca9e.cdf-ms    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_61efdd9e2d0263ca.cdf-ms    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\program_files_reference_assemblies_microsoft_framework_v3.0_44577d982216c291.cdf-ms    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\PresentationCore.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\PresentationFramework.dll    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\ReachFramework.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\System.Printing.dll    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WindowsBase.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\PresentationCore.dll    : 0x119c      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\PresentationFramework.dll    : 0x10f0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\ReachFramework.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\System.Printing.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\WindowsBase.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\diasymreader.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordacwks.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscordbi.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll    : 0xf38      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\peverify.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\SOS.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Core.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Data.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\System.Xaml.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\NativeImages\mscorlib.ni.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PenIMC.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PenIMC2_v0400.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PenIMC_v0400.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationCore.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework-SystemData.dll    : 0x11a4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationFramework.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationHost_v0400.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\PresentationNative_v0400.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\System.Windows.Controls.Ribbon.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClient.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationClientsideProviders.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationProvider.dll    : 0xf38      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\UIAutomationTypes.dll    : 0xf74      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WindowsBase.dll    : 0xf68      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\wpfgfx_v0400.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\en-US\PresentationHost_v0400.dll.mui    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscordacwks.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorlib.dll    : 0x11a0      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\SOS.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.Data.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v2.0.50727\System.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PenIMC.dll    : 0xc50      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationHostDLL.dll    : 0xd08      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:33                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\wpfgfx_v0300.dll    : 0xefc      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:34                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:07:35                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\_0000000000000000.cdf-ms    : 0x1288      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$.cdf-ms    : 0x12c4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_21ffbdd2a2dd92e0.cdf-ms    : 0x11d4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_syswow64_advancedinstallers_0c6bb4866bff02f7.cdf-ms    : 0x1288      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_21f9a9c4a2f8b514.cdf-ms    : 0x12c4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_system32_advancedinstallers_dfe2cf200b391371.cdf-ms    : 0x11d4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_servicing_fc2045b9046cc796.cdf-ms    : 0x1288      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_servicing_version_10.0.19041.3205_887f436b8d1c623a.cdf-ms    : 0x1288      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_servicing_sqm_51d9d5f9de5a2fa5.cdf-ms    : 0x11d4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_servicing_sessions_5591aee9e2456a35.cdf-ms    : 0x12c4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_servicing_packages_46c20bc5f833cc43.cdf-ms    : 0x1288      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\WinSxS\FileMaps\$$_logs_cbs_10a752bcbbaee88b.cdf-ms    : 0x11d4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : ?     :  S:ARAI(AU;SAFA;0x1f0116;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\poqexec.exe    : 0x12c4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\poqexec.exe    : 0x11d4      :    : 0x860    : C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.2905_none_7dd39c4c7cb9dfa0\TiWorker.exe     :     : S:AINO_ACCESS_CONTROL     :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:07:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2a50    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   12544      2023-07-19 14:07:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:07:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:08:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:08:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:10:13                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x730    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:10:13                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x730    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:10:13                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x730    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:10:13                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x730    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-19 14:13:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:13:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x16f4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x16f4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x16f4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x16f4    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:14:58                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   13826      2023-07-19 14:16:01                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x2fd4    :  C:\Windows\System32\VSSVC.exe  
      Audit Success   12544      2023-07-19 14:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:16:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:18:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:18:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:18:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:18:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:20:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:20:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:20:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:20:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:22:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:22:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:22:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:22:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:22:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:22:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 14:29:58                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:29:59                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:00                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:02                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:03                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:04                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 14:30:05                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 14:37:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:37:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:37:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:37:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:39:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:39:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:39:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 14:40:22                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x15dc    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 14:41:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:41:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:48:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:48:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 14:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 14:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 14:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 14:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:08:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:08:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:08:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 15:08:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:08:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:08:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:08:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:08:29                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:29                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:29                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:08:29                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3684    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-19 15:08:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:08:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:10:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:10:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:18:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:18:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 15:18:19                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 15:18:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:18:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:18:24                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:24                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:24                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 15:18:24                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x4a8    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-19 15:23:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:23:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:23:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:23:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 15:31:06                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:38:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:42:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:42:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:42:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:42:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:42:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:42:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 15:44:08                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x15dc    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:48:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:52:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:52:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:52:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:52:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 15:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 15:59:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 15:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 15:59:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:04:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:04:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:04:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:08:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:08:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:08:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 16:29:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 16:29:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:29:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 16:29:06                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:06                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:06                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   13824      2023-07-19 16:29:06                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3aac    :  C:\Windows\System32\taskhostw.exe  
      Audit Success   12544      2023-07-19 16:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:39:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 16:42:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:42:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:42:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:48:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:48:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 16:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 16:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:01:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:01:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:07:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:11:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:11:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:29:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 17:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 17:31:01                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 17:44:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:44:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:44:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:44:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:44:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:44:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 17:59:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 18:10:30                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x15dc    :  C:\Windows\explorer.exe  
      Audit Success   12544      2023-07-19 18:11:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 18:11:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:11:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 18:11:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:11:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:11:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 18:13:37                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:13:38                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 18:22:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:22:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 18:38:33                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 18:45:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:45:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 18:57:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 18:57:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:10:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:10:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:17:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:17:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:25:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:25:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:28:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:28:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 19:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 19:35:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:35:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:42:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:42:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:42:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:42:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:42:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:42:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:42:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:42:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:42:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 19:42:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:42:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 19:42:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:53:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:53:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:55:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:55:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:56:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 19:56:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 19:56:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 19:57:57                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:57:57                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 19:57:57                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 20:09:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:09:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:19:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:19:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13826      2023-07-19 20:19:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin      :    :  0x24c4    :  C:\Windows\System32\svchost.exe  
      Audit Success   13826      2023-07-19 20:19:42                                  Microsoft-Windows-Security-Auditing  4799:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin      :    :  0x24c4    :  C:\Windows\System32\svchost.exe  
      Audit Success   12544      2023-07-19 20:22:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:22:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:32:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:32:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:36:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:36:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:36:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:36:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:36:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:36:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 20:36:41                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 20:36:41                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 20:36:41                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 20:47:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:47:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:49:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:49:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:49:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 20:49:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:49:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 20:49:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:49:37                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:01                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 20:50:26                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 20:50:26                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 20:50:26                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 20:56:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 20:56:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:01:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:01:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:09:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:09:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:10:54                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 21:10:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:10:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:19:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:19:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:29:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:29:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 21:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 21:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 21:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 21:31:00                                  Microsoft-Windows-Security-Auditing  5382:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12544      2023-07-19 21:31:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:31:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 21:31:32                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 21:31:32                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   13824      2023-07-19 21:31:32                                  Microsoft-Windows-Security-Auditing  5381:    .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c      ,       .  
      Audit Success   12290      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :  0x6609c     :    : Microsoft Software Key Storage Provider    : RSA    : TB_0_microsoft.com    : %%2500     :   : %%2480    : 0x0  
      Audit Success   12544      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:17                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8099      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   13824      2023-07-19 21:41:18                                  Microsoft-Windows-Security-Auditing  5379:      .    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :  %%8100      ,            .  
      Audit Success   12544      2023-07-19 21:44:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:44:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:44:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:44:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:51:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 21:51:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:51:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 21:51:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:51:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:51:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:51:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12544      2023-07-19 21:51:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:51:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12548      2023-07-19 21:51:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:52:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:52:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   12544      2023-07-19 21:57:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ALEXANDER_PC$     :  WORKGROUP    :  0x3e7      :    :  5     : -     :  %%1843    :  %%1842     :  %%1833     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7     :  0x0      : -      : -   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -        :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,     .     ""      ,  .   ,   "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .     " "          .                .   - GUID     ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -   " "     .      "0",     .  
      Audit Success   12548      2023-07-19 21:57:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege     SeDelegateSessionUserImpersonatePrivilege  
      Audit Success   13824      2023-07-19 21:57:56                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3490    :  C:\Program Files\WinRAR\WinRAR.exe  
      Audit Success   13824      2023-07-19 21:58:11                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x15dc    :  C:\Windows\explorer.exe  
      Audit Success   13824      2023-07-19 21:59:06                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:01:29                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x6609c    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x3b48    :  C:\Program Files\WinRAR\WinRAR.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-503     :  DefaultAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-504     :  WDAGUtilityAccount     :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-500     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
      Audit Success   13824      2023-07-19 22:03:05                                  Microsoft-Windows-Security-Auditing  4798:      .    Subject:    :  S-1-5-21-1169138220-2165426419-3855891747-1001     :       :  ALEXANDER_PC    :  0x65ff5    :    :  S-1-5-21-1169138220-2165426419-3855891747-501     :       :  ALEXANDER_PC      :    :  0x127c    :  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe  
                  212        2023-07-18 22:09:47                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16A4&MI_03&Col02\8&2761191&0&0001.  
                  212        2023-07-18 22:09:47                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16DF&MI_03&Col02\8&2c632188&0&0001.  
                            2023-07-18 22:10:11                                  Service Control Manager         7023:  "  "  -    %%21  
                            2023-07-18 22:11:22                                  Service Control Manager         7030:  "Uncheater for BattleGrounds_GL"   ,        .    .  
                  212        2023-07-18 22:11:49                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16A4&MI_03&Col02\8&2761191&0&0001.  
                  212        2023-07-18 22:11:50                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16DF&MI_03&Col02\8&2c632188&0&0001.  
                            2023-07-18 22:13:59                                  Service Control Manager         7030:  "    "   ,        .    .  
                          2023-07-18 22:16:33                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-18 22:16:36                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-19 01:09:34                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                  212        2023-07-19 10:14:50                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16A4&MI_03&Col02\8&2761191&0&0001.  
                  212        2023-07-19 10:14:50                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16DF&MI_03&Col02\8&2c632188&0&0001.  
                          2023-07-19 10:15:19                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-19 10:15:24                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-19 10:17:00                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.SecurityAppBroker    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                          2023-07-19 10:17:00                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.WscBrokerManager    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                          2023-07-19 10:17:00                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.WscDataProtection    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                  212        2023-07-19 13:59:47                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16A4&MI_03&Col02\8&2761191&0&0001.  
                  212        2023-07-19 13:59:47                           Microsoft-Windows-Kernel-PnP    219:    \Driver\WudfRd   HID\VID_0951&PID_16DF&MI_03&Col02\8&2c632188&0&0001.  
                          2023-07-19 14:00:17                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-19 14:00:22                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                          2023-07-19 14:01:57                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.SecurityAppBroker    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                          2023-07-19 14:01:57                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.WscBrokerManager    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                          2023-07-19 14:01:57                           DCOM                            10016:             COM-  CLSID   Windows.SecurityCenter.WscDataProtection    APPID       NT AUTHORITY\    (S-1-5-18)   LocalHost (  LRPC),         ().           .
                          2023-07-19 14:03:02                         DCOM                            10016:              COM-  CLSID   {C2F03A33-21F5-47FA-B4BB-156362A2F239}    APPID   {316CDED5-E4AE-4B15-9113-7055D84DCC97}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),     Microsoft.Windows.ShellExperienceHost_10.0.19041.1949_neutral_neutral_cw5n1h2txyewy    (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708).           .
                          2023-07-19 14:03:09                         DCOM                            10016:              COM-  CLSID   {C2F03A33-21F5-47FA-B4BB-156362A2F239}    APPID   {316CDED5-E4AE-4B15-9113-7055D84DCC97}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),     Microsoft.Windows.ShellExperienceHost_10.0.19041.1949_neutral_neutral_cw5n1h2txyewy    (S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708).           .
                          2023-07-19 14:08:01                         DCOM                            10016:             COM-  CLSID   {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}    APPID   {15C20B67-12E7-4BB6-92BB-7AFF07997402}    ALEXANDER_PC\    (S-1-5-21-1169138220-2165426419-3855891747-1001)   LocalHost (  LRPC),         ().           .
                            2023-07-19 20:36:12                                  nvlddmkm                        0: 
                          2023-07-19 20:36:13                                  Display                         4101:  nvlddmkm      .  


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  AMD K17 - Root Complex
                  
      Offset 000:  22 10 50 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  22 10 50 14 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  80 00 00 00  10 00 80 00 
      Offset 050:  22 10 50 14  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  60 99 05 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  08 01 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 E0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 30 14  04 02 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 0D0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0E0:  46 00 30 01  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 80 80 00  00 00 00 00  FF FF FF FF 

    B00 D00 F02:  AMD K17 - IOMMU
                  
      Offset 000:  22 10 51 14  00 00 10 00  00 00 06 08  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  22 10 51 14 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  FF 00 00 00 
      Offset 040:  0F 64 0B 19  01 00 B8 FE  00 00 00 00  00 00 00 00 
      Offset 050:  40 30 20 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  05 74 85 00  00 00 E0 FE  00 00 00 00 
      Offset 070:  CE 40 00 00  08 00 03 A8  22 10 51 14  00 2B 00 00 
      Offset 080:  DA 1A 20 62  CF CF 03 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  02 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  BF 07 00 2C  10 9C 73 0E  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  75 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  FF FF FF FF  00 00 00 00  FF FF FF FF 

    B00 D01 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D01 F01:  AMD K17 - PCIe GPP Bridge [7:0]
                  
      Offset 000:  22 10 53 14  06 04 10 00  00 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  F1 01 00 00 
      Offset 020:  80 F7 80 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  22 80 00 00 
      Offset 060:  30 21 00 00  43 78 73 01  40 00 43 70  00 00 04 00 
      Offset 070:  00 00 40 01  08 00 01 00  00 00 00 00  BF 01 70 00 
      Offset 080:  06 00 00 00  0E 00 00 00  03 00 1F 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 81 00  0C F0 E2 FE  00 00 00 00  60 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D C8 00 00  22 10 53 14  08 00 03 A8  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D01 F03:  AMD K17 - PCIe GPP Bridge [7:0]
                  
      Offset 000:  22 10 53 14  07 04 10 00  00 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 06 00  F1 F1 00 20 
      Offset 020:  50 F7 60 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  22 80 00 00 
      Offset 060:  10 21 00 00  43 F8 72 02  40 00 43 70  00 00 04 00 
      Offset 070:  00 00 40 01  08 00 01 00  00 00 00 00  BF 01 70 00 
      Offset 080:  06 00 00 00  0E 00 00 00  03 00 1F 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 81 00  0C F0 E2 FE  00 00 00 00  50 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D C8 00 00  22 10 53 14  08 00 03 A8  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D03 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D03 F01:  AMD K17 - PCIe GPP Bridge [7:0]
                  
      Offset 000:  22 10 53 14  07 04 10 00  00 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 07 07 00  E1 E1 00 20 
      Offset 020:  00 F6 00 F7  01 E0 F1 F1  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 00 18 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  22 80 00 00 
      Offset 060:  30 29 00 00  03 79 73 00  40 00 03 F1  00 00 04 00 
      Offset 070:  00 00 40 01  08 00 01 00  00 00 00 00  BF 01 70 00 
      Offset 080:  06 00 00 00  0E 00 00 00  03 00 1F 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 81 00  0C F0 E2 FE  00 00 00 00  B1 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D C8 00 00  22 10 53 14  08 00 03 A8  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D04 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D07 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D07 F01:  AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C
                  
      Offset 000:  22 10 54 14  06 04 10 00  00 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 08 08 00  F1 01 00 00 
      Offset 020:  20 F7 40 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 00  22 80 00 00 
      Offset 060:  30 21 00 00  03 0D 70 00  40 00 03 71  00 00 00 00 
      Offset 070:  00 00 40 00  08 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  0E 00 00 00  43 00 1F 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 81 00  0C F0 E2 FE  00 00 00 00  A1 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D C8 00 00  22 10 54 14  08 00 03 A8  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D08 F00:  AMD K17 - PCIe Dummy Host Bridge
                  
      Offset 000:  22 10 52 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D08 F01:  AMD K17 - Internal PCIe GPP Bridge 0 to Bus B/C
                  
      Offset 000:  22 10 54 14  06 04 10 00  00 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 09 09 00  F1 01 00 00 
      Offset 020:  70 F7 70 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 00  22 80 00 00 
      Offset 060:  30 21 00 00  03 0D 70 00  40 00 03 71  00 00 00 00 
      Offset 070:  00 00 40 00  08 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  0E 00 00 00  43 00 1F 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 81 00  0C F0 E2 FE  00 00 00 00  91 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D C8 00 00  22 10 54 14  08 00 03 A8  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  AMD K17 FCH - SMBus and ACPI Controller
                  
      Offset 000:  22 10 0B 79  03 04 20 02  59 00 05 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  58 14 01 50 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  AMD K17 FCH - LPC Bridge
                  
      Offset 000:  22 10 0E 79  0F 00 20 02  51 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  58 14 01 50 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  04 00 00 00  D5 FF 03 FF  07 FF 20 03  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  40 FF 41 FF  40 16 00 0A  00 00 0F 00  00 FF FF FF 
      Offset 070:  67 45 23 00  00 00 00 00  90 02 00 00  07 0A 00 00 
      Offset 080:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  50 0A 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  02 00 C1 FE  2F 01 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  04 00 E9 3F  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 80  00 00 F7 FF 
      Offset 0D0:  86 FF FD 08  42 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD K17 - Data Fabric: Device 18h; Function 0
                  
      Offset 000:  22 10 60 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  13 00 00 00  2F 12 97 00  1F 1F 1F 0F  11 00 00 00 
      Offset 050:  1F 07 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  41 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  01 00 00 00  00 00 00 00  05 04 04 04  04 04 04 04 
      Offset 0A0:  43 00 00 09  40 00 00 00  40 00 00 00  40 00 00 00 
      Offset 0B0:  40 00 00 00  40 00 00 00  40 00 00 00  40 00 00 00 
      Offset 0C0:  13 E0 00 00  04 F0 00 00  00 00 00 00  04 00 00 00 
      Offset 0D0:  00 00 00 00  04 00 00 00  00 00 00 00  04 00 00 00 
      Offset 0E0:  00 00 00 00  04 00 00 00  00 00 00 00  04 00 00 00 
      Offset 0F0:  00 00 00 00  04 00 00 00  00 00 00 00  04 00 00 00 

    B00 D18 F01:  AMD K17 - Data Fabric: Device 18h; Function 1
                  
      Offset 000:  22 10 61 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  05 05 04 04  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 42 42 42  FF 01 FF 01  E0 00 00 00  00 00 00 00 
      Offset 0B0:  01 00 00 00  00 00 00 00  08 00 00 00  00 00 00 00 
      Offset 0C0:  01 00 00 00  81 FC 06 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  1F BF 1F 0B 
      Offset 0F0:  0F 5D 1D 05  1F 7F BF 05  1F BF FF 03  0F 57 F7 01 

    B00 D18 F02:  AMD K17 - Data Fabric: Device 18h; Function 2
                  
      Offset 000:  22 10 62 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  80 10 1F 00  08 09 40 09  80 00 00 00  11 00 00 00 
      Offset 050:  04 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  19 50 06 00  11 06 04 10 
      Offset 070:  00 01 00 02  00 04 00 08  00 10 00 20  00 40 00 80 
      Offset 080:  0F DF 00 00  FF DF 00 00  07 00 00 06  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD K17 - Data Fabric: Device 18h; Function 3
                  
      Offset 000:  22 10 63 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  04 00 00 00  00 00 00 00  01 00 00 00  27 01 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F04:  AMD K17 - Data Fabric: Device 18h; Function 4
                  
      Offset 000:  22 10 64 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  51 10 01 00  41 18 03 00  00 00 00 00  89 01 04 00 
      Offset 060:  08 02 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  04 00 00 00  04 00 00 00  04 00 00 00  04 00 00 00 
      Offset 090:  22 10 60 14  22 10 60 14  00 00 00 00  00 00 00 00 
      Offset 0A0:  43 00 00 00  43 00 00 00  22 10 60 14  22 10 60 14 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 00 00 00  01 00 02 00  00 00 02 01  03 0B 0E 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F05:  AMD K17 - Data Fabric: Device 18h; Function 5
                  
      Offset 000:  22 10 65 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 D7 01  01 00 00 00  01 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  80 00 00 00 

    B00 D18 F06:  AMD K17 - Data Fabric: Device 18h; Function 6
                  
      Offset 000:  22 10 66 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 0F 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F07:  AMD K17 - Data Fabric: Device 18h; Function 7
                  
      Offset 000:  22 10 67 14  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F00:    NVM Express [144D-A808] [NoDB]
                  
      Offset 000:  4D 14 08 A8  06 04 10 00  00 02 08 01  10 00 00 00 
      Offset 010:  04 00 80 F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  4D 14 01 A8 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  01 50 03 00  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 70 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 B0 02 00  C1 8F 00 10  37 20 00 00  43 78 47 00 
      Offset 080:  40 00 43 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  1F 08 00 00  00 00 00 00  0E 00 00 00 
      Offset 0A0:  03 00 1F 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  11 00 20 80  00 30 00 00  00 20 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  03 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:   - AMD USB 3.10  1.10 () [1022-43D5] [NoDB]
                  
      Offset 000:  22 10 D5 43  06 04 10 00  01 30 03 0C  10 00 80 00 
      Offset 010:  04 00 6A F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  21 1B 42 11 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 68 86 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  31 40 00 00  00 00 00 00  11 78 07 80  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  08 00 00 00 
      Offset 080:  10 00 12 00  22 8C 00 00  17 21 19 00  43 DC 42 00 
      Offset 090:  40 00 43 10  00 00 00 00  00 00 40 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 08 00 00  00 00 00 00  0E 00 00 00 
      Offset 0B0:  03 00 06 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  21 1B 01 02  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 01 60  00 00 00 00  00 00 00 00 
      Offset 0F0:  AA 55 AA 55  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F01:    SATA AHCI [1022-43C8] [NoDB]
                  
      Offset 000:  22 10 C8 43  00 04 10 00  01 01 06 01  10 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 68 F7  00 00 00 00  21 1B 62 10 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 78 80 00  0C F0 E2 FE  00 00 00 00  81 49 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  11 78 07 00  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  0B 01 00 00 
      Offset 080:  10 00 12 00  22 8C 00 00  17 21 19 00  43 DC 42 00 
      Offset 090:  40 00 43 10  00 00 00 00  00 00 40 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  0E 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  21 1B 01 02  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  CC 0D 00 00  01 01 01 01  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F02:   PCI Express Upstream Switch [1022-43C6] [NoDB]
                  
      Offset 000:  22 10 C6 43  07 04 10 00  01 00 04 06  10 00 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  02 03 06 00  F1 F1 00 00 
      Offset 020:  50 F7 50 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  05 03 00 00 
      Offset 040:  04 00 C3 FE  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 050:  05 78 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  11 78 07 00  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  08 00 00 00 
      Offset 080:  10 C0 52 00  22 80 00 00  17 21 19 00  43 DC 42 00 
      Offset 090:  40 00 43 10  00 00 00 00  00 00 40 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  0E 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D 00 00 00  21 1B 01 02  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B03 D00 F00:   PCI Express Downstream Switch [1022-43C7] [NoDB]
                  
      Offset 000:  22 10 C7 43  07 04 10 00  01 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  03 04 04 00  F1 F1 00 00 
      Offset 020:  50 F7 50 F7  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  0B 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 78 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  11 78 07 00  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  08 00 00 00 
      Offset 080:  10 C0 62 01  22 80 00 00  17 21 10 00  12 7C 73 00 
      Offset 090:  40 00 11 70  00 0D 08 00  00 00 48 01  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 08 00 00  00 00 00 00  06 00 00 00 
      Offset 0B0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D 00 00 00  21 1B 06 33  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B03 D01 F00:   PCI Express Downstream Switch [1022-43C7] [NoDB]
                  
      Offset 000:  22 10 C7 43  04 04 10 00  01 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  03 05 05 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  0A 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 78 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  11 78 07 00  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  08 00 00 00 
      Offset 080:  10 C0 62 01  22 80 00 00  17 21 10 00  12 7C 73 01 
      Offset 090:  00 00 11 10  00 0D 08 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 08 00 00  00 00 00 00  06 00 00 00 
      Offset 0B0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D 00 00 00  21 1B 06 33  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B03 D04 F00:   PCI Express Downstream Switch [1022-43C7] [NoDB]
                  
      Offset 000:  22 10 C7 43  04 04 10 00  01 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  03 06 06 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  0B 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 78 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  11 78 07 00  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 C0  08 00 00 00 
      Offset 080:  10 C0 62 01  22 80 00 00  17 21 10 00  42 7C 73 04 
      Offset 090:  00 00 01 10  00 0D 08 00  00 00 08 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 08 00 00  00 00 00 00  06 00 00 00 
      Offset 0B0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  0D 00 00 00  21 1B 06 33  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B04 D00 F00:  Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter
                  
      Offset 000:  EC 10 68 81  07 04 10 00  16 00 00 02  10 00 00 00 
      Offset 010:  01 F0 00 00  00 00 00 00  04 40 50 F7  00 00 00 00 
      Offset 020:  04 00 50 F7  00 00 00 00  00 00 00 00  58 14 00 E0 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  01 50 C3 FF  08 01 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 70 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 B0 02 02  C0 8C 68 00  17 50 10 00  11 7C 47 00 
      Offset 080:  40 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  1F 08 0C 00  10 00 00 00  02 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  11 00 03 80  04 00 00 00  04 08 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B07 D00 F00:  NVIDIA GeForce RTX 3060 [10DE-2504] [NoDB]
                  
      Offset 000:  DE 10 04 25  07 04 10 00  A1 00 00 03  10 00 80 00 
      Offset 010:  00 00 00 F6  0C 00 00 E0  00 00 00 00  0C 00 00 F0 
      Offset 020:  00 00 00 00  01 E0 00 00  00 00 00 00  58 14 74 40 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  58 14 74 40  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  01 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 48  08 00 00 00  05 78 81 00  0C F0 E2 FE 
      Offset 070:  00 00 00 00  64 49 00 00  10 B4 12 00  E1 8D 00 10 
      Offset 080:  37 29 00 00  03 4D 45 00  40 00 03 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  13 00 07 00 
      Offset 0A0:  00 00 00 00  1E 00 80 01  03 00 1F 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  09 00 14 01  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  11 00 05 00  00 00 B9 00 
      Offset 0D0:  00 00 BA 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B07 D00 F01:   High Definition Audio (Microsoft) [10DE-228E] [NoDB]
                  
      Offset 000:  DE 10 8E 22  06 00 10 00  A1 00 03 04  10 00 80 00 
      Offset 010:  00 00 08 F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  58 14 74 40 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  37 02 00 00 
      Offset 040:  58 14 74 40  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 00 02 00  E1 8D 00 00 
      Offset 080:  37 21 09 00  03 4D 45 00  40 00 03 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  13 00 07 00 
      Offset 0A0:  00 00 00 00  1E 00 80 01  00 00 01 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B08 D00 F00:  AMD K17 - PCIe Dummy Function
                  
      Offset 000:  22 10 5A 14  04 04 10 00  00 00 00 13  10 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  22 10 5A 14 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  FF 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  22 10 5A 14 
      Offset 050:  01 64 03 00  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  10 00 02 00  A1 8F 00 00  30 21 00 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  03 00 1F 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B08 D00 F02:  AMD K17 - Cryptographic Coprocessor PSPCPP
                  
      Offset 000:  22 10 56 14  00 04 10 00  00 00 80 10  10 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 40 F7  00 00 00 00 
      Offset 020:  00 00 00 00  00 E0 3F F7  00 00 00 00  22 10 56 14 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  00 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  22 10 56 14 
      Offset 050:  01 64 03 00  0B 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  10 A0 02 00  A1 8F 00 00  30 21 00 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 82 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  11 00 01 00  05 00 00 00  05 10 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B08 D00 F03:  AMD K17 - Reserved
                  
      Offset 000:  22 10 5F 14  06 04 10 00  00 30 03 0C  10 00 80 00 
      Offset 010:  04 00 20 F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  58 14 07 50 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  00 03 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  58 14 07 50 
      Offset 050:  01 64 03 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  30 20 00 00  10 A0 02 00  A1 8F 00 00  30 21 10 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 C0 86 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  11 00 07 80  00 E0 0F 00  00 F0 0F 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B09 D00 F00:  AMD K17 - PCIe Dummy Function
                  
      Offset 000:  22 10 55 14  04 04 10 00  00 00 00 13  10 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  22 10 55 14 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  FF 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  22 10 55 14 
      Offset 050:  01 64 03 00  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  10 00 02 00  A1 8F 00 00  30 21 00 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  03 00 1F 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B09 D00 F02:  AMD K17 FCH - SATA AHCI Controller
                  
      Offset 000:  22 10 01 79  00 04 10 00  51 01 06 01  10 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 80 70 F7  00 00 00 00  58 14 02 B0 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  00 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  58 14 02 B0 
      Offset 050:  01 64 23 C0  0B 01 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  10 A0 02 00  A1 8F 00 00  30 21 00 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 D0 B8 00  0C F0 E2 FE  00 00 00 00  B8 49 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  12 00 10 00  0F 00 00 00  00 00 00 00  00 FF 37 F7 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B09 D00 F03:  AMD K17 - High Definition Audio Controller
                  
      Offset 000:  22 10 57 14  06 00 10 00  00 00 03 04  10 00 80 00 
      Offset 010:  00 80 7F F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  58 14 82 A1 
      Offset 030:  00 00 00 00  48 00 00 00  00 00 00 00  2B 03 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  09 50 08 00  58 14 82 A1 
      Offset 050:  01 64 03 C8  08 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  10 A0 02 00  A1 8F 00 00  30 21 00 00 
      Offset 070:  03 0D 40 00  40 00 03 11  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  1F 00 00 00  00 00 00 00 
      Offset 090:  0E 00 00 00  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.z.K7400.L.w.VIDEO ....p.....IBM VGA Compatible.......X07/27/21
    C000:0040  ..........P......D%.PMID.7.7...........JGV-N3060GAMING OC-12GD/F
    C000:0080  X0/0CAA..................................................Version
    C000:00C0   94.06.25.40.05 ...Copyright (C) 1996-2021 NVIDIA Corp..........
    C000:0100  ....GPU Board..........................Chip Rev   ..............
    C000:0140  ................................................PCIR...%........
    C000:0180  z...............NPDE...........X.t@..............BIT......E2...
    C000:01C0  8.B.%.D.C.,.i.D.....I.$...M.)...N.....P.....S.....T.....U.....V.
    C000:0200  ....x.....d.....p.....u.....i.n...E..........>.}m...............
    C000:0240  ....@%....................\\(...<....RR..QO....... ..........g+.
    C000:0280  .........2!..p!..."..oP..O?....S?...?S?...?...>v.....O}........?
    C000:02C0  .@[......._P..m...y....'...F...G...H..i.........................
    C000:0300  ..................d...........:...^...............+...........I.
    C000:0340  ...............B..4B...B......!...b...............C.......9...U,
    C000:0380  ......+#...$..F%...&...(...(..!'..A....................+..r.....
    C000:03C0  ..-...K.......h.P.....(.N..N#..#'...O((R....0O....E6D..........l


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    HDA Codec       nVIDIA Unknown (10DE009Fh / 14584074h)
    HDD             Samsung SSD 970 EVO 500GB
    Monitor ID      MSI3CA7:   PnP [NoDB]
    Monitor Model   MSI G273
    Motherboard     63-0100-000001-00101111-022718-Chipset$8A16BG08_BIOS DATE: 12/18/19 10:08:46 VER: 05.0000E
    Motherboard     DMIMOBO: Gigabyte Technology Co., Ltd. B450 AORUS ELITE
    Motherboard     DMISYS: Gigabyte Technology Co., Ltd. B450 AORUS ELITE
    Motherboard     Unknown
    PCI/AGP         1022-43C6 [SubSys: 0000-0000]:  PCI Express Upstream Switch [1022-43C6] [NoDB]
    PCI/AGP         1022-43C7 [SubSys: 0000-0000]:  PCI Express Downstream Switch [1022-43C7] [NoDB]
    PCI/AGP         1022-43C8 [SubSys: 1B21-1062]:   SATA AHCI [1022-43C8] [NoDB]
    PCI/AGP         1022-43D5 [SubSys: 1B21-1142]:  - AMD USB 3.10  1.10 () [1022-43D5] [NoDB]
    PCI/AGP         10DE-228E [SubSys: 1458-4074]:  High Definition Audio (Microsoft) [10DE-228E] [NoDB]
    PCI/AGP         10DE-2504 [SubSys: 1458-4074]: NVIDIA GeForce RTX 3060 [10DE-2504] [NoDB]
    PCI/AGP         144D-A808 [SubSys: 144D-A801]:   NVM Express [144D-A808] [NoDB]
    SSD             Samsung SSD 970 EVO 500GB


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
