Escalation of Privileges in a Windows Environment by User WinEventLog:Security Go Splunk 6 4 Escalation of Privileges in a Windows Environment by user. sourcetype="WinEventLog:Security" (EventCode=576 OR EventCode=4672 OR EventCode=577 OR EventCode=4673 OR EventCode=578 OR EventCode=4674) | stats count by user 1 sourcetype="WinEventLog:Security" (EventCode=576 OR EventCode=4672 OR EventCode=577 OR EventCode=4673 OR EventCode=578 OR EventCode=4674) | stats count by user Share This: Tagged: 6.1.2Escalation of PrivilegesSecurityWindowsWindows Security