pslist causes security audit log failure on non-administrative user account

Posted by Woot4Moo on Server Fault See other posts from Server Fault or by Woot4Moo
Published on 2010-06-08T19:14:44Z Indexed on 2010/06/08 19:23 UTC
Read the original article Hit count: 598

Filed under:
|
|

The user has RX privs. This event consistently arises in the security logs. How can this be resolved? Or what is the underlying issue here? Some additional information the user has local login disabled and log on as a service enabled.

Failure Audit 
Category: Object Access
Event ID 560
Object Server: Security
Object Type: File
Object Name: Pg_control
Image File Name: xx/xx/xx/xx postgres.exe
Primary User name: my_User

Object Open:
    Object Server:  Security
    Object Type:    Key
    Object Name:    \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Performance
Handle ID:  -
Operation ID:   {0,26727190}
Process ID: 2492
Image File Name:    C:\Program Files\tomcat\webapps\myApp\bin\win32\pslist.exe
Primary User Name:  my_user
Primary Domain: KFHFTZ03
Primary Logon ID:   (0x0,0x178D9)
Client User Name:   -
Client Domain:  -
Client Logon ID:    -
Accesses:   READ_CONTROL 
        Query key value 
        Set key value 
        Create sub-key 
        Enumerate sub-keys 
        Notify about changes to keys 

Privileges: -
Restricted Sid Count:   0
Access Mask:    0x2001

© Server Fault or respective owner

Related posts about failure

Related posts about security-audit