Escalation of Privileges in a Windows Environment by User WinEventLog:Security Go Splunk Vote Up +8 Vote Down -4You already voted! Escalation of Privileges in a Windows Environment by user. sourcetype="WinEventLog:Security" (EventCode=576 OR EventCode=4672 OR EventCode=577 OR EventCode=4673 OR EventCode=578 OR EventCode=4674) | stats count by user Share This: Tagged: 6.1.2Escalation of PrivilegesSecurityWindowsWindows Security