SeRestorePrivilege allows file content modification, even if the security descriptor on the file might not grant such access. This function can also be used to change the owner and protection. SeChangeNotifyPrivilege allows traverse right. … In this case, the file system makes a policy decision to enforce this privilege.
What is SeAuditPrivilege?
AKA: SeAuditPrivilege, Generate security audits. Note: This is an admin-equivalent right. Default assignment: Local System (This default assignment does not show up in Local Security Policy. It is implicit.) This extremely sensitive right allows you to report events to the security log using the ReportEvent() API.
What is a privileged service was called?
4673: A privileged service was called. Event 4673 indicates that the specified user exercised the user right specified in the Privileges field. Note: “User rights” and “privileges” are synonymous terms used interchangeably in Windows. Some user rights are logged by this event – others by 4674.