Windows 10: Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...

Discus and support Security Audit Event ID 4797 "An attempt was made to query the existence of a blank... in AntiVirus, Firewalls and System Security to solve the problem; I'm currently parsing through event viewer on our devices and I've noticed a few cases of Event ID 4797, which states: An attempt was made to query... Discussion in 'AntiVirus, Firewalls and System Security' started by DaxTheBadger, Jan 20, 2020.

  1. Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...


    I'm currently parsing through event viewer on our devices and I've noticed a few cases of Event ID 4797, which states:

    An attempt was made to query the existence of a blank password for an account

    Could I get a little guidance on what this exactly means and a good course of action to take? What are the chances that some of these could be false positives?

    :)
     
    DaxTheBadger, Jan 20, 2020
    #1
  2. PDC
    PdC Win User

    Windows Security Event Log - Periodic 4672 events with Account Name: SYSTEM

    I'm seeing periodic 4672 events (Special Logon) in my Windows Home 10 workstation.

    What triggered my interest is that the events triggered by Security ID / Account name "SYSTEM", is that they occur at regular intervals over the last 12 hours.

    This occurs almost on the hour, overnight.

    Then this morning I see an event 4797 (User account management) "An attempt was made to query the existence of a blank password for an account."

    An attempt was made to query the existence of a blank password for an account.

    This event is only seen once.

    So my question is two-fold, what are the regular SYSTEM 4672 events and are they somehow related to the 4796 (User Account Management) event?

    Thanks.
     
  3. windows 10 event id 10 - An attempt was made to query the existence of a blank password for an account.

    Hello Steve,

    Security auditing is a powerful tool to help maintain the security of an enterprise. Auditing can be used for a variety of purposes, including forensic analysis, regulatory compliance, monitoring user activity, and troubleshooting. Industry regulations in
    various countries or regions require enterprises to implement a strict set of rules related to data security and privacy. Security audits can help implement such policies and prove that these policies have been implemented. Also, security auditing can be used
    for forensic analysis, to help administrators detect anomalous behavior, to identify and mitigate gaps in security policies, and to deter irresponsible behavior by tracking critical user activities. You can check this
    article for more information.

    Furthermore, you received this even when the Audit User Account Management
    is enabled, it generates audit events when specific user account management tasks are performed. The level of auditing is informational and not a warning or error. The said event is normal and can be safely ignored. The purpose is to check if by any chance
    a user is set for a Blank password so that users doesn't see a password box before they sign in when they have no password.

    Let me know if you have other concerns.

    Regards.
     
    Melchizedek Qui, Jan 20, 2020
    #3
  4. Techie_DD Win User

    Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...

    Windows 10 workstation Security log filling with Event ID 4703

    My Windows 10 workstation's Security Event Log is filled with informational Event ID 4703 (like 20/second).

    It's an Audit Success on Authorization Policy Change category.

    Pretty much all are about the javaw.exe process & SeSecurityPrivilege. But also a few of them list svchost.exe as the process & a whole list of privileges.

    I can't find anything on the Net about event 4703.

    Sometimes it lists the privilege as Disabled (as below), and some are Enabled. Back & forth, multiple events per second.

    Does anyone have any idea what/why this is, or anyone else experiencing it?

    Here are the details of the event (edited for privacy)...

    Task Category: Authorization Policy Change

    Level: Information

    Keywords: Audit Success

    User: N/A

    Computer: xxxxx.yyyy.com

    Description:

    A user right was adjusted.

    Subject:

    Security ID: SYSTEM

    Account Name: XXXXXX

    Account Domain: YYYYYYYY

    Logon ID: 0x3E7

    Target Account:

    Security ID: SYSTEM

    Account Name: XXXXXXX

    Account Domain: YYYYYYYYY

    Logon ID: 0x3E7

    Process Information:

    Process ID: 0xb24

    Process Name: C:\Windows\SysWOW64\ContegoSPOP\jre1.7.0_65\bin\javaw.exe

    Enabled Privileges:

    -

    Disabled Privileges:

    SeSecurityPrivilege
     
    Techie_DD, Jan 20, 2020
    #4
Thema:

Security Audit Event ID 4797 "An attempt was made to query the existence of a blank...

Loading...
  1. Security Audit Event ID 4797 "An attempt was made to query the existence of a blank... - Similar Threads - Security Audit Event

  2. An attempt was made to reference a token that does not exist

    in Windows 10 Gaming
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  3. An attempt was made to reference a token that does not exist

    in Windows 10 Software and Apps
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  4. An attempt was made to reference a token that does not exist

    in Windows 10 Installation and Upgrade
    An attempt was made to reference a token that does not exist: An attempt was made to reference a token that does not exist https://answers.microsoft.com/en-us/windows/forum/all/an-attempt-was-made-to-reference-a-token-that-does/a57ff71c-ab85-4d31-860a-cf8f90d12db5
  5. Excessive "Audit Success" log events for event ID 5061 and 5058

    in Windows 10 Gaming
    Excessive "Audit Success" log events for event ID 5061 and 5058: I'm getting these 2 event IDs logged every 5 seconds in my Security log on Windows 11 Pro.This seems excessive. Also unsure why this is happening like clockwork, regardless what I'm doing on my laptop.Anyone else seeing this? Wondering whether I can/need to update my Audit...
  6. windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...

    in AntiVirus, Firewalls and System Security
    windows server 2012 Event id 4979 - An attempt was made to query the existence of a blank...: When I log in to the window server 2012. the account may trigger the server to query the existence of a blank password for all of the local account in the server Event ID 4979 In the security event log, there will be a list of action logged to indicate that my account...
  7. Event ID Error 157 Security Query

    in Windows 10 Support
    Event ID Error 157 Security Query: I noticed an Event ID Error 157 as noted below. Is it recommended to run the command bcdedit /set hypervisorschedulertype core? Log Name: System Source: Microsoft-Windows-Hyper-V-Hypervisor Date: 05/09/2020 06:21:59 Event ID: 157 Task Category: None Level: Warning Keywords:...
  8. Event ID 10016 Fix Query

    in Windows 10 BSOD Crashes and Debugging
    Event ID 10016 Fix Query: Good day everyone, regarding to this Fix https://answers.microsoft.com/en-us/windows/forum/windows8_1-winapps/weather-application/e4630db3-50c2-4cc5-9813-f089494a1145 for Event ID 10016. I would like to ask the instruction on number 5, when it says to apply full...
  9. An attempt was made to reference a token that does not exist

    in Windows 10 News
    An attempt was made to reference a token that does not exist: [ATTACH] [ATTACH]If your Windows File Explorer has stopped working and you see an error while trying to open it – An attempt was made to reference a token that does not exist, then this post may be able to help you. [...] This post An attempt was made to reference a token...
  10. Too Many 'Audit Success' Security-Auditing Events Happening

    in Windows 10 Performance & Maintenance
    Too Many 'Audit Success' Security-Auditing Events Happening: Hi! I've been using Windows 10 for a while now and except for one time where my start button and notification tray stopped working (solved that by migrating to a new user account), I haven't had any problems. Except maybe a week ago. Consistently during use (either for...