4624201254400x8020000000000000391752Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfa26993KerberosKerberos-{1F811612-FACB-9941-C9C7-431151ED3011}--00x0-10.0.1.1457995%%1833---%%18430x0%%1842 4688201331200x8020000000000000336756Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x11c8C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336757Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xdfcC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336758Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x954C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336759Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x15a8C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336761Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x155cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336760Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x47cC:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336762Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x9fcC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4634001254500x8020000000000000391754Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfa3f173 4624201254400x8020000000000000391753Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfa3f173KerberosKerberos-{DAF19F92-2D62-44D5-0B91-62483890BE28}--00x0-::158004%%1833---%%18430x0%%1842 4634001254500x8020000000000000391758Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfa6ec63 4624201254400x8020000000000000391757Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfa6ec63KerberosKerberos-{1F811612-FACB-9941-C9C7-431151ED3011}--00x0-10.0.1.1458012%%1833---%%18430x0%%1842 4634001254500x8020000000000000391756Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfa6dbe3 4624201254400x8020000000000000391755Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfa6dbe3KerberosKerberos-{1F811612-FACB-9941-C9C7-431151ED3011}--00x0-10.0.1.1458011%%1833---%%18430x0%%1842 4688201331200x8020000000000000336763Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xa88C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336764Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xa6cC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336765Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x7ccC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336767Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xe28C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336766Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1488C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336768Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1214C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336769Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x15dcC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4634001254500x8020000000000000391759Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfa26993 4634001254500x8020000000000000391761Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfa7fec3 4624201254400x8020000000000000391760Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfa7fec3KerberosKerberos-{DAF19F92-2D62-44D5-0B91-62483890BE28}--00x0-::158020%%1833---%%18430x0%%1842 4688201331200x8020000000000000336770Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x3c8C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336771Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xd08C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336772Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xdf8C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336774Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1034C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336773Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x15b0C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336775Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1614C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4634001254500x8020000000000000391768Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfab4e13 4634001254500x8020000000000000391767Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfab5d13 4634001254500x8020000000000000391766Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfab6223 4624201254400x8020000000000000391765Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfab71b3KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-fe80::ac51:1fb3:8580:881858031%%1840---%%18430x0%%1842 4624201254400x8020000000000000391764Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfab6223KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-10.0.1.1458030%%1833---%%18430x0%%1842 4624201254400x8020000000000000391763Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfab5d13KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-::10%%1833---%%18430x0%%1842 4624201254400x8020000000000000391762Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfab4e13KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-fe80::ac51:1fb3:8580:881858029%%1833---%%18430x0%%1842 4688201331200x8020000000000000336776Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x730C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4634001254500x8020000000000000391769Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfab71b3 4634001254500x8020000000000000391771Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfac3853 4624201254400x8020000000000000391770Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfac3853KerberosKerberos-{DAF19F92-2D62-44D5-0B91-62483890BE28}--00x0-::158036%%1833---%%18430x0%%1842 4688201331200x8020000000000000336777Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x8fcC:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336778Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xb80C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336779Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x254C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336781Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1740C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336780Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x115cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4688201331200x8020000000000000336782Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x14e4C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4719001356800x8020000000000000391779Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0x3e7%%8273%%12548{0CCE921B-69AE-11D9-BED3-505054503030}%%8449, %%8451 4634001254500x8020000000000000391778Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb02433 4634001254500x8020000000000000391777Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb03333 4634001254500x8020000000000000391776Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb03833 4624201254400x8020000000000000391775Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb04623KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-fe80::ac51:1fb3:8580:881858046%%1840---%%18430x0%%1842 4624201254400x8020000000000000391774Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb03833KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-10.0.1.1458045%%1833---%%18430x0%%1842 4624201254400x8020000000000000391773Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb03333KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-::10%%1833---%%18430x0%%1842 4624201254400x8020000000000000391772Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb02433KerberosKerberos-{C4EBD96D-E93E-E3C7-CA33-77F0CECE7F9E}--00x0-fe80::ac51:1fb3:8580:881858044%%1833---%%18430x0%%1842 4688201331200x8020000000000000336783Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1654C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4634001254500x8020000000000000391780Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb04623 4634001254500x8020000000000000391783Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb176e3 4624201254400x8020000000000000391782Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb176e3KerberosKerberos-{DAF19F92-2D62-44D5-0B91-62483890BE28}--00x0-::158051%%1833---%%18430x0%%1842 4672001254800x8020000000000000391781Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb176eSeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege 4688201331200x8020000000000000336784Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f20x1068C:\Tools\PurpleSharp\PurpleSharp.exe%%19380x314PurpleSharp.exe /pb pb2.jsonNULL SID--0x0C:\Windows\System32\cmd.exeMandatory Label\Medium Mandatory Level 4624201254400x8020000000000000391788Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0ATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE.LOCAL0xfb1a9c3KerberosKerberos-{E6E6EA15-EDF7-2314-AB47-237B4EA173D2}--00x0-10.0.1.1550967%%1833---%%18430x0%%1842 4624201254400x8020000000000000391787Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0ATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE.LOCAL0xfb1a8a3KerberosKerberos-{E6E6EA15-EDF7-2314-AB47-237B4EA173D2}--00x0-10.0.1.1550966%%1833---%%18430x0%%1842 4624201254400x8020000000000000391786Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0ATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE.LOCAL0xfb1a2e3KerberosKerberos-{E6E6EA15-EDF7-2314-AB47-237B4EA173D2}--00x0-10.0.1.1550965%%1833---%%18430x0%%1842 4634001254500x8020000000000000391785Securitywin-dc-mvelazco-02713-392.attackrange.localATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE0xfb1a173 4624201254400x8020000000000000391784Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0ATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE.LOCAL0xfb1a173KerberosKerberos-{E6E6EA15-EDF7-2314-AB47-237B4EA173D2}--00x0-10.0.1.1550964%%1833---%%18430x0%%1842 4625001254400x8010000000000000391790Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMONROE_YATESattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550970 4776001433600x8010000000000000391789Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MONROE_YATESWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336785Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MONROE_YATESattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391792Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDLENORE_MCCULLOUGHattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550972 4776001433600x8010000000000000391791Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0LENORE_MCCULLOUGHWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336786Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}LENORE_MCCULLOUGHattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336787Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}DALE_STANLEYattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391794Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDDALE_STANLEYattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550973 4776001433600x8010000000000000391793Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0DALE_STANLEYWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336788Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}RUSTY_SPENCERattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391796Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDRUSTY_SPENCERattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550974 4776001433600x8010000000000000391795Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0RUSTY_SPENCERWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391798Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDDONNELL_MICHAELattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550975 4776001433600x8010000000000000391797Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0DONNELL_MICHAELWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336789Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}DONNELL_MICHAELattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391800Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDDOLORES_NEWTONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550976 4776001433600x8010000000000000391799Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0DOLORES_NEWTONWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336790Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}DOLORES_NEWTONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336791Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}HERMINIA_EATONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391802Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDHERMINIA_EATONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550978 4776001433600x8010000000000000391801Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0HERMINIA_EATONWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391804Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDCHRISTINA_HUFFattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550979 4776001433600x8010000000000000391803Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0CHRISTINA_HUFFWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336792Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}CHRISTINA_HUFFattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336793Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MAUREEN_FINCHattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4624201254400x8020000000000000391808Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb404c3KerberosKerberos-{F559ACCA-36BF-A6F5-5C2C-C444979B9784}--00x0-10.0.1.1458055%%1840---%%18430x0%%1842 4672001254800x8020000000000000391807Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb404cSeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege 4625001254400x8010000000000000391806Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMAUREEN_FINCHattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550981 4776001433600x8010000000000000391805Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MAUREEN_FINCHWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391810Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SID479341857SAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550982 4776001433600x8010000000000000391809Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0479341857SAWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336794Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}479341857SAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391812Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDCALLIE_LLOYDattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550983 4776001433600x8010000000000000391811Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0CALLIE_LLOYDWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336795Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}CALLIE_LLOYDattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336796Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}ELMO_PETERSattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391814Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDELMO_PETERSattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550985 4776001433600x8010000000000000391813Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0ELMO_PETERSWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391816Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMARCELO_ARMSTRONGattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550986 4776001433600x8010000000000000391815Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MARCELO_ARMSTRONGWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336797Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MARCELO_ARMSTRONGattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336798Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JIMMY_HORTONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391818Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJIMMY_HORTONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550987 4776001433600x8010000000000000391817Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JIMMY_HORTONWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391820Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDBENNETT_BASSattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550988 4776001433600x8010000000000000391819Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0BENNETT_BASSWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336799Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}BENNETT_BASSattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336800Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}BROCK_PITTMANattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391822Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDBROCK_PITTMANattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550989 4776001433600x8010000000000000391821Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0BROCK_PITTMANWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336801Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}TRISTAN_CAMPBELLattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391824Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDTRISTAN_CAMPBELLattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550991 4776001433600x8010000000000000391823Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0TRISTAN_CAMPBELLWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391826Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDEARLE_SYKESattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550992 4776001433600x8010000000000000391825Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0EARLE_SYKESWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336802Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}EARLE_SYKESattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336803Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MILDRED_KLINEattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391828Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMILDRED_KLINEattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550993 4776001433600x8010000000000000391827Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MILDRED_KLINEWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391831Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDCEDRIC_CLAYattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550994 4776001433600x8010000000000000391830Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0CEDRIC_CLAYWIN-HOST-MVELAZ0xc000006a 4634001254500x8020000000000000391829Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb404c3 4648001254400x8020000000000000336804Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}CEDRIC_CLAYattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391833Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJENNIFER_ACOSTAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550995 4776001433600x8010000000000000391832Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JENNIFER_ACOSTAWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336805Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JENNIFER_ACOSTAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391835Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMEREDITH_PADILLAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550996 4776001433600x8010000000000000391834Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MEREDITH_PADILLAWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336806Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MEREDITH_PADILLAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391837Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDLEON_CASHattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550998 4776001433600x8010000000000000391836Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0LEON_CASHWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336807Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}LEON_CASHattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391839Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJENNY_KENNEDYattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1550999 4776001433600x8010000000000000391838Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JENNY_KENNEDYWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336808Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JENNY_KENNEDYattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4688201331200x8020000000000000336810Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x10a4C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-admon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4648001254400x8020000000000000336809Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}ALDO_CARROLLattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391841Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDALDO_CARROLLattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551000 4776001433600x8010000000000000391840Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0ALDO_CARROLLWIN-HOST-MVELAZ0xc000006a 4688201331200x8020000000000000336813Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1314C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-MonitorNoHandle.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4648001254400x8020000000000000336812Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JEAN_WALLattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4688201331200x8020000000000000336811Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x37cC:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-netmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4625001254400x8010000000000000391843Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJEAN_WALLattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551001 4776001433600x8010000000000000391842Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JEAN_WALLWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336814Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}NEIL_KELLEYattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391845Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDNEIL_KELLEYattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551002 4776001433600x8010000000000000391844Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0NEIL_KELLEYWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336815Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MATILDA_MCGEEattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391847Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMATILDA_MCGEEattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551004 4776001433600x8010000000000000391846Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MATILDA_MCGEEWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391849Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMAMIE_BOYLEattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551005 4776001433600x8010000000000000391848Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MAMIE_BOYLEWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336816Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MAMIE_BOYLEattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4688201331200x8020000000000000336819Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70xf2cC:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4648001254400x8020000000000000336818Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}HUMBERTO_OLSENattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4688201331200x8020000000000000336817Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1448C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-powershell.exe" --ps2NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4625001254400x8010000000000000391851Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDHUMBERTO_OLSENattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551006 4776001433600x8010000000000000391850Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0HUMBERTO_OLSENWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336821Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}KENT_DIXONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391853Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDKENT_DIXONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551007 4776001433600x8010000000000000391852Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KENT_DIXONWIN-HOST-MVELAZ0xc000006a 4688201331200x8020000000000000336820Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x1510C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-regmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4648001254400x8020000000000000336822Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}CAROLE_MIRANDAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391855Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDCAROLE_MIRANDAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551008 4776001433600x8010000000000000391854Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0CAROLE_MIRANDAWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336823Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}ALFREDA_ZIMMERMANattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391857Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDALFREDA_ZIMMERMANattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551009 4776001433600x8010000000000000391856Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0ALFREDA_ZIMMERMANWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336824Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}LLOYD_ABBOTTattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391859Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDLLOYD_ABBOTTattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551011 4776001433600x8010000000000000391858Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0LLOYD_ABBOTTWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336825Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}KRISTOPHER_BENTLEYattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391861Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDKRISTOPHER_BENTLEYattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551012 4776001433600x8010000000000000391860Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0KRISTOPHER_BENTLEYWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336826Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}MAE_COLEMANattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391863Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDMAE_COLEMANattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551013 4776001433600x8010000000000000391862Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0MAE_COLEMANWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336827Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}919497906SAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391865Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SID919497906SAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551014 4776001433600x8010000000000000391864Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0919497906SAWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391867Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDDONALD_ROBERTSattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551015 4776001433600x8010000000000000391866Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0DONALD_ROBERTSWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336829Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}DONALD_ROBERTSattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4688201331200x8020000000000000336828Securitywin-host-mvelazco-02713-447.attackrange.localNT AUTHORITY\SYSTEMWIN-HOST-MVELAZ$ATTACKRANGE0x3e70x155cC:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe%%19360x7d4"C:\Program Files\SplunkUniversalForwarder\bin\splunk-winprintmon.exe"NULL SID--0x0C:\Program Files\SplunkUniversalForwarder\bin\splunkd.exeMandatory Label\System Mandatory Level 4625001254400x8010000000000000391869Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDRON_VANCEattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551016 4776001433600x8010000000000000391868Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0RON_VANCEWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336830Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}RON_VANCEattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336831Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}WOODROW_HENDERSONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391871Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDWOODROW_HENDERSONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551018 4776001433600x8010000000000000391870Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0WOODROW_HENDERSONWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336832Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}DAPHNE_PENAattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391873Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDDAPHNE_PENAattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551019 4776001433600x8010000000000000391872Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0DAPHNE_PENAWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336833Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}SHELLEY_MANNattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391875Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDSHELLEY_MANNattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551020 4776001433600x8010000000000000391874Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0SHELLEY_MANNWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336834Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}SAMMY_PIERCEattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391877Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDSAMMY_PIERCEattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551021 4776001433600x8010000000000000391876Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0SAMMY_PIERCEWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336835Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JAN_PARSONSattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391879Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJAN_PARSONSattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551022 4776001433600x8010000000000000391878Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JAN_PARSONSWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336836Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}LIZ_CHANGattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391881Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDLIZ_CHANGattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551024 4776001433600x8010000000000000391880Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0LIZ_CHANGWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336837Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}JOSUE_HOWARDattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391883Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDJOSUE_HOWARDattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551025 4776001433600x8010000000000000391882Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0JOSUE_HOWARDWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336838Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}ROSS_JACKSONattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391885Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDROSS_JACKSONattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551026 4776001433600x8010000000000000391884Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0ROSS_JACKSONWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336839Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}ALDEN_BROWNattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391887Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDALDEN_BROWNattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551027 4776001433600x8010000000000000391886Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0ALDEN_BROWNWIN-HOST-MVELAZ0xc000006a 4625001254400x8010000000000000391889Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDVIRGINIA_REIDattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551028 4776001433600x8010000000000000391888Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0VIRGINIA_REIDWIN-HOST-MVELAZ0xc000006a 4648001254400x8020000000000000336840Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}VIRGINIA_REIDattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4648001254400x8020000000000000336841Securitywin-host-mvelazco-02713-447.attackrange.localATTACKRANGE\REED_LARSENreed_larsenATTACKRANGE0x1360f2{00000000-0000-0000-0000-000000000000}GEOFFREY_SARGENTattackrange.local{00000000-0000-0000-0000-000000000000}win-dc-mvelazco-02713-392.attackrange.localwin-dc-mvelazco-02713-392.attackrange.local0x410.0.1.14445 4625001254400x8010000000000000391891Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NULL SIDGEOFFREY_SARGENTattackrange.local0xc000006d%%23130xc000006a3NtLmSsp NTLMWIN-HOST-MVELAZ--00x0-10.0.1.1551030 4776001433600x8010000000000000391890Securitywin-dc-mvelazco-02713-392.attackrange.localMICROSOFT_AUTHENTICATION_PACKAGE_V1_0GEOFFREY_SARGENTWIN-HOST-MVELAZ0xc000006a 4634001254500x8020000000000000391894Securitywin-dc-mvelazco-02713-392.attackrange.localATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE0xfb1a9c3 4634001254500x8020000000000000391893Securitywin-dc-mvelazco-02713-392.attackrange.localATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE0xfb1a2e3 4634001254500x8020000000000000391892Securitywin-dc-mvelazco-02713-392.attackrange.localATTACKRANGE\REED_LARSENREED_LARSENATTACKRANGE0xfb1a8a3 4634001254500x8020000000000000391897Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb5afd3 4624201254400x8020000000000000391896Securitywin-dc-mvelazco-02713-392.attackrange.localNULL SID--0x0NT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE.LOCAL0xfb5afd3KerberosKerberos-{DAF19F92-2D62-44D5-0B91-62483890BE28}--00x0-::158065%%1833---%%18430x0%%1842 4672001254800x8020000000000000391895Securitywin-dc-mvelazco-02713-392.attackrange.localNT AUTHORITY\SYSTEMWIN-DC-MVELAZCO$ATTACKRANGE0xfb5afdSeSecurityPrivilege SeBackupPrivilege SeRestorePrivilege SeTakeOwnershipPrivilege SeDebugPrivilege SeSystemEnvironmentPrivilege SeLoadDriverPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege SeEnableDelegationPrivilege