Events 528/576 caused by

This is a discussion about Events 528/576 caused by in the Windows Security category; Occasionally I see a pair of entries in the event viewer security log that are attributed to anonymous user. Event 1: Event ID: 528 User: NTAuthority/anonymous Computer: (name of computer) Source: Security Type: Success Audit Catagory: Logon/Logoff Description: Successful Logon: User Name: (blank) Domain (blank) Lo ...

Windows Security 292 This topic was started by ,


data/avatar/default/avatar24.webp

12 Posts
Location -
Joined 2004-10-30
Occasionally I see a pair of entries in the event viewer security log that are attributed to "anonymous user".
 
Event 1:
 
Event ID: 528
User: NTAuthority/anonymous
Computer: (name of computer)
Source: Security
Type: Success Audit
Catagory: Logon/Logoff
Description:
Successful Logon:
User Name: (blank)
Domain (blank)
Login Id: (0x0,0x3639)
Logon Type: 3
Logon Process: KSecDD
Authentication Process:
Microsoft_Authentication_Package_V1_0
Workstation name: (blank)
 
 
Event 2:
 
Event ID:576
User: NT Authority/anonymous
Computer: (name of computer)
Source: Security
Type: Success Audit
Catagory: Privilege Use
Description:
Special privileges assigned to new logon:
User name; (blank)
Domain: (blank)
Login ID: (0x0,0x3635)
Assigned: SechangeNotifyPrivilege
 
 
They come in pairs, same date and time stamp. the item "0x36nn" seems to change a little, but it's always "0x36nn".
 
The item (blank) is really blank, empty space. The item (name of computer) is the name of the workstation.
 
There is no "anonymous" user in the user manager. System is NT4 server, SP6.
 
Should I be concerned with these items? If not, what are they?
 
Why is their no user name printed?
 
What is the Login ID?
 
 
 

Participate in our website and join the conversation

You already have an account on our website? To log in, use the link provided below.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This subject has been archived. New comments and votes cannot be submitted.
Feb 25
Created
Feb 25
Last Response
0
Likes
1 minute
Read Time
User User
Users

Responses to this topic


data/avatar/default/avatar09.webp

1019 Posts
Location -
Joined 2004-12-21
Quote:
Should I be concerned with these items? If not, what are they?

No, it is normal. See this:
Quote:
[url=
http://www.derkeiler.com/Newsgroups/comp...02-02/0194.html
" title="httpwwwderkeilercomNewsgroupscomposmswindowsntadminsecurity2002020194html titlehttpwwwderkeilercomNewsgroupscomposmswindowsntadminsecurity2002020194htmlurlhttpwwwderkeilercomNewsgroupscomposmswindowsntadminsecurity2002020194html relnofollow targetblankhttpwwwderkeilercomNewsgroupscomp02020194html"> http://www.derkeiler.com/Newsgroups/comp...0194.html

This is quite normal and shouldn't alarm you too much. The
'SeChangeNotifyPrivilege' is an advanced permission and bypasses traverse checking.


Quote:
Why is their no user name printed?

It is anonymous.. sorry, do not know. Perhaps it is Windows' internal activity which will not log username.