IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Audit and Remediation: Why Are Some User Accounts Missing When Querying the Services Table?

Audit and Remediation: Why Are Some User Accounts Missing When Querying the Services Table?

Environment

  • Audit and Remediation Console: All Versions
  • Carbon Black Cloud Sensor: All Supported Versions
  • Microsoft Windows: All Supported Versions

Question

Why do queries where user_account is retrieved from the services table return blank values for some Windows services?

Answer

Instances of per-user services are not populated with user account metadata in Windows.

Additional Notes

  • This missing metadata can be verified in services.msc by reviewing the impacted service under Properties > Log On > User Account or in regedit.msc by checking for an ObjectName value for the service under Computer\HKLM\SYSTEM\CurrentControlSet\Services.
  • Windows assigns unique names to per-user services by adding the logon session LUID as a suffix (e.g. CaptureService_123ab).

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-22-2023
Views:
369
Contributors