Windows Event ID 11: Policy.vpol File Created Process (lsass.exe)
Windows Event ID 11 is generated by the Microsoft-Windows-Sysmon/Operational event logs when a Policy.vpol file is created by the Local Security Authority Subsystem Service (lsass.exe). This event can provide valuable information for security analysts and system administrators to monitor and investigate potential security threats.
Overview of Event ID 11
Event ID 11 is generated when the Sysmon driver detects that the lsass.exe process has created a Policy.vpol file. The Policy.vpol file is used to define the user rights assignment policies on a Windows system. These policies specify which users and groups have access to specific system resources and operations.
Key Concepts
- Sysmon: A Windows system service and driver that monitors and logs security-related events.
- lsass.exe: The Local Security Authority Subsystem Service, which is responsible for enforcing security policy on a Windows system.
- Policy.vpol file: A file that defines the user rights assignment policies on a Windows system.
Interpreting Event ID 11
When Event ID 11 is generated, it indicates that the lsass.exe process has created a Policy.vpol file. This event can be used to monitor changes to the user rights assignment policies on a Windows system. If this event is generated unexpectedly, it may indicate a potential security threat, such as a malicious user or process attempting to elevate their privileges on the system.
Example Event ID 11 Entry
Event ID 11
Task Category: Operational
Level: Informational
Keywords: Audit Failure
Description: The Local Security Authority Subsystem Service (lsass.exe) created a Policy.vpol file.
References
This article provided information on Windows Event ID 11, Policy.vpol file created process (lsass.exe). It covered key concepts, interpretation, example event ID 11 entry, and references. The event can be used to monitor changes to the user rights assignment policies on a Windows system. If this event is generated unexpectedly, it may indicate a potential security threat, such as a malicious user or process attempting to elevate their privileges on the system.