<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Opera keeps calling SeTcbPrivilege]]></title><description><![CDATA[<p dir="auto">We use Security Onion in our office and we keep getting OSSEC alerts because Opera keeps trying to elevate privileges which fails which in turn triggers a security audit alert.  We don't want to turn the alert off nor filter that event out.</p>
<p dir="auto">Was wondering if anyone else has come across this<br />
.<br />
{"timestamp":"2019-03-06T20:05:15.116+0000","rule":{"level":10,"description":"Windows: Multiple failed attempts to perform a privileged operation by the same user.","id":"18151","frequency":6,"firedtimes":550,"mail":true,"groups":["windows"],"pci_dss":["10.2.4","10.2.5","11.4"],"gdpr":["IV_35.7.d","IV_32.2"]},"agent":{"id":"005","name":"SN-WKS-08","ip":"192.168.150.211"},<br />
"manager":{"name":"SN-LAB-SEC01"},"id":"1551902715.1103192234","previous_output":"2019 Mar 06 13:04:55 WinEvtLog: Security: AUDIT_FAILURE(4673):<br />
Microsoft-Windows-Security-Auditing: (no user): no domain: <a href="http://SN-WKS-08.ad.XXXX.ca" target="_blank" rel="noopener noreferrer nofollow ugc">SN-WKS-08.ad.XXXX.ca</a>: A privileged service was called.    Subject:<br />
Security ID:  S-1-5-21-2358658803-1195769352-62849749-1226   Account Name:  XXXX   Account Domain:  AD   Logon ID:  0x281183    Service:   Server: Security<br />
Service Name: -    Process:<br />
Process ID: 0x2a6c<br />
Process Name: C:\Users\XXXX\AppData\Local\Programs\Opera\58.0.3135.79\opera.exe<br />
Service Request Information:<br />
Privileges:  SeTcbPrivilege\n2019 Mar 06 13:04:55</p>
]]></description><link>https://forums.opera.com/topic/31268/opera-keeps-calling-setcbprivilege</link><generator>RSS for Node</generator><lastBuildDate>Sat, 07 Mar 2026 01:38:15 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/31268.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 07 Mar 2019 16:06:26 GMT</pubDate><ttl>60</ttl></channel></rss>