1. Windows Access Control

Windows Control Mechanisms for identifying the source of an operation and determine sufficient privileges:


Security Identifiers (SID):

S-R-X-Y

S = Indicates that it is a SID
R = Revision. Always set to 1
X = Identifier authority. Eg. 5 for NT Authority
Y = Sub-authorities of identifier authority.

S-1-5-21-1336799502-1441772794-948155058-1001
S-1-0-0                       Nobody        
S-1-1-0	                      Everybody
S-1-5-11                      Authenticated Users
S-1-5-18                      Local System
S-1-5-domainidentifier-500    Administrator

Access tokens:

Mandatory Integrity Control (MIC)

User Account Control (UAC):