Tracing the source of an SID...

Discussion in 'other security issues & news' started by Thelps, May 6, 2018.

  1. Thelps

    Thelps Registered Member

    Joined:
    Apr 1, 2012
    Posts:
    46
    Found a Security Identifier (SID) listed under Security Permissions on this PC.

    It begins S-1-15-3. You read that right, S-1-15-3.

    Could anyone explain what this SID prefix means? Microsoft don't list this prefix on their SID prefix page.

    How can I trace what was the IP of the computer that created this SID?

    If it wasn't a remote connection how can I trace what application or account created and/or used this SID?

    This has been a project of mine for quite some time.
     
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Are you on Windows 10? Here is one similar question: https://social.technet.microsoft.co...using-the-flood-of-dcom?forum=win10itprosetup
    ... and one of the answers:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.