Elastic Windows Event Explorer


Publisher - Microsoft-Windows-Crypto-RSAEnh

Event ID 14

Message:

Attempting to write key container info.

 Process: 	%{ProcessName}
 Provider Type: 	%{ProviderType}
 Container Name: 	%{ContainerName}
 Machine Keyset: 	%{MachineKeyset}

Event Data:

# Name In Type
Out Type
1 ProcessName win:UnicodeString xs:string
2 ProviderType win:UInt32 xs:unsignedInt
3 ContainerName win:UnicodeString xs:string
4 MachineKeyset win:Boolean xs:boolean

Observed Windows Versions:

Version: 0

Fingerprint: 4IN5WVSPQNKVG