pslist causes security audit log failure on non-administrative user account
- by Woot4Moo
The user has RX privs. This event consistently arises in the security logs. How can this be resolved? Or what is the underlying issue here? Some additional information the user has local login disabled and log on as a service enabled.
Failure Audit
Category: Object Access
Event ID 560
Object Server: Security
Object Type: File
Object Name: Pg_control
Image File Name: xx/xx/xx/xx postgres.exe
Primary User name: my_User
Object Open:
Object Server: Security
Object Type: Key
Object Name: \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Performance
Handle ID: -
Operation ID: {0,26727190}
Process ID: 2492
Image File Name: C:\Program Files\tomcat\webapps\myApp\bin\win32\pslist.exe
Primary User Name: my_user
Primary Domain: KFHFTZ03
Primary Logon ID: (0x0,0x178D9)
Client User Name: -
Client Domain: -
Client Logon ID: -
Accesses: READ_CONTROL
Query key value
Set key value
Create sub-key
Enumerate sub-keys
Notify about changes to keys
Privileges: -
Restricted Sid Count: 0
Access Mask: 0x2001