﻿<?xml version="1.0" encoding="utf-8"?>
<Events>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:28:29.0000000Z" />
      <EventRecordID>4880</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:12:16.0000000Z" />
      <EventRecordID>4879</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:09:23.0000000Z" />
      <EventRecordID>4878</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:21:36.0000000Z" />
      <EventRecordID>4877</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:43:06.0000000Z" />
      <EventRecordID>4876</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:40:58.0000000Z" />
      <EventRecordID>4875</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:45:42.0000000Z" />
      <EventRecordID>4874</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:36:44.0000000Z" />
      <EventRecordID>4873</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:59:52.0000000Z" />
      <EventRecordID>4872</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:06:43.0000000Z" />
      <EventRecordID>4871</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:41:01.0000000Z" />
      <EventRecordID>4870</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:03:53.0000000Z" />
      <EventRecordID>4869</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:07:04.0000000Z" />
      <EventRecordID>4868</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:35:32.0000000Z" />
      <EventRecordID>4867</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:29:33.0000000Z" />
      <EventRecordID>4866</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:16:21.0000000Z" />
      <EventRecordID>4865</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:27:46.0000000Z" />
      <EventRecordID>4864</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:07:28.0000000Z" />
      <EventRecordID>4863</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:11:14.0000000Z" />
      <EventRecordID>4862</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:19:31.0000000Z" />
      <EventRecordID>4861</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:27:15.0000000Z" />
      <EventRecordID>4860</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:16:36.0000000Z" />
      <EventRecordID>4859</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:08:15.0000000Z" />
      <EventRecordID>4858</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:16:18.0000000Z" />
      <EventRecordID>4857</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:55:21.0000000Z" />
      <EventRecordID>4856</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:37:59.0000000Z" />
      <EventRecordID>4855</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:17:23.0000000Z" />
      <EventRecordID>4854</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:17:52.0000000Z" />
      <EventRecordID>4853</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:22:05.0000000Z" />
      <EventRecordID>4852</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:48:40.0000000Z" />
      <EventRecordID>4851</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:44:06.0000000Z" />
      <EventRecordID>4850</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:45:44.0000000Z" />
      <EventRecordID>4849</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:09:11.0000000Z" />
      <EventRecordID>4848</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:02:35.0000000Z" />
      <EventRecordID>4847</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:37:45.0000000Z" />
      <EventRecordID>4846</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:22:39.0000000Z" />
      <EventRecordID>4845</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:04:31.0000000Z" />
      <EventRecordID>4844</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:31:43.0000000Z" />
      <EventRecordID>4843</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:39:08.0000000Z" />
      <EventRecordID>4842</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:08:32.0000000Z" />
      <EventRecordID>4841</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:06:06.0000000Z" />
      <EventRecordID>4840</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:01:06.0000000Z" />
      <EventRecordID>4839</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:52:50.0000000Z" />
      <EventRecordID>4838</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:22:11.0000000Z" />
      <EventRecordID>4837</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:58:26.0000000Z" />
      <EventRecordID>4836</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:46:26.0000000Z" />
      <EventRecordID>4835</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:05:47.0000000Z" />
      <EventRecordID>4834</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:03:58.0000000Z" />
      <EventRecordID>4833</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:52:23.0000000Z" />
      <EventRecordID>4832</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:06:59.0000000Z" />
      <EventRecordID>4831</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:23:15.0000000Z" />
      <EventRecordID>4830</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:58:47.0000000Z" />
      <EventRecordID>4829</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:32:39.0000000Z" />
      <EventRecordID>4828</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:13:20.0000000Z" />
      <EventRecordID>4827</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:18:11.0000000Z" />
      <EventRecordID>4826</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:09:42.0000000Z" />
      <EventRecordID>4825</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:38:03.0000000Z" />
      <EventRecordID>4824</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:23:02.0000000Z" />
      <EventRecordID>4823</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:09:21.0000000Z" />
      <EventRecordID>4822</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:56:53.0000000Z" />
      <EventRecordID>4821</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:29:58.0000000Z" />
      <EventRecordID>4820</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:31:48.0000000Z" />
      <EventRecordID>4819</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:03:06.0000000Z" />
      <EventRecordID>4818</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:51:15.0000000Z" />
      <EventRecordID>4817</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:59:16.0000000Z" />
      <EventRecordID>4816</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:57:38.0000000Z" />
      <EventRecordID>4815</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:06:27.0000000Z" />
      <EventRecordID>4814</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:34:40.0000000Z" />
      <EventRecordID>4813</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:53:01.0000000Z" />
      <EventRecordID>4812</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:01:37.0000000Z" />
      <EventRecordID>4811</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:06:08.0000000Z" />
      <EventRecordID>4810</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:16:39.0000000Z" />
      <EventRecordID>4809</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:51:07.0000000Z" />
      <EventRecordID>4808</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:23:10.0000000Z" />
      <EventRecordID>4807</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:37:04.0000000Z" />
      <EventRecordID>4806</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:23:27.0000000Z" />
      <EventRecordID>4805</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:43:09.0000000Z" />
      <EventRecordID>4804</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:41:15.0000000Z" />
      <EventRecordID>4803</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:45:21.0000000Z" />
      <EventRecordID>4802</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:18:10.0000000Z" />
      <EventRecordID>4801</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:28:17.0000000Z" />
      <EventRecordID>4800</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:15:05.0000000Z" />
      <EventRecordID>4799</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:22:07.0000000Z" />
      <EventRecordID>4798</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:48:51.0000000Z" />
      <EventRecordID>4797</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:09:47.0000000Z" />
      <EventRecordID>4796</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:59:01.0000000Z" />
      <EventRecordID>4795</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:16:22.0000000Z" />
      <EventRecordID>4794</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:23:02.0000000Z" />
      <EventRecordID>4793</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:56:40.0000000Z" />
      <EventRecordID>4792</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:04:52.0000000Z" />
      <EventRecordID>4791</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:53:14.0000000Z" />
      <EventRecordID>4790</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:49:46.0000000Z" />
      <EventRecordID>4789</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:56:26.0000000Z" />
      <EventRecordID>4788</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:55:35.0000000Z" />
      <EventRecordID>4787</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:42:38.0000000Z" />
      <EventRecordID>4786</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:46:36.0000000Z" />
      <EventRecordID>4785</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:25:33.0000000Z" />
      <EventRecordID>4784</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:24:54.0000000Z" />
      <EventRecordID>4783</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:26:37.0000000Z" />
      <EventRecordID>4782</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:42:36.0000000Z" />
      <EventRecordID>4781</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:14:06.0000000Z" />
      <EventRecordID>4780</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:13:31.0000000Z" />
      <EventRecordID>4779</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:25:05.0000000Z" />
      <EventRecordID>4778</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:34:06.0000000Z" />
      <EventRecordID>4777</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:05:27.0000000Z" />
      <EventRecordID>4776</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:38:44.0000000Z" />
      <EventRecordID>4775</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:38:24.0000000Z" />
      <EventRecordID>4774</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:54:05.0000000Z" />
      <EventRecordID>4773</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:00:02.0000000Z" />
      <EventRecordID>4772</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:50:03.0000000Z" />
      <EventRecordID>4771</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:04:10.0000000Z" />
      <EventRecordID>4770</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:27:24.0000000Z" />
      <EventRecordID>4769</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:30:52.0000000Z" />
      <EventRecordID>4768</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:01:04.0000000Z" />
      <EventRecordID>4767</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:04:39.0000000Z" />
      <EventRecordID>4766</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:54:59.0000000Z" />
      <EventRecordID>4765</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:34:00.0000000Z" />
      <EventRecordID>4764</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:21:22.0000000Z" />
      <EventRecordID>4763</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:23:28.0000000Z" />
      <EventRecordID>4762</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:21:02.0000000Z" />
      <EventRecordID>4761</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:24:19.0000000Z" />
      <EventRecordID>4760</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:22:18.0000000Z" />
      <EventRecordID>4759</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:43:11.0000000Z" />
      <EventRecordID>4758</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:53:33.0000000Z" />
      <EventRecordID>4757</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:39:54.0000000Z" />
      <EventRecordID>4756</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:01:19.0000000Z" />
      <EventRecordID>4755</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:59:45.0000000Z" />
      <EventRecordID>4754</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:50:28.0000000Z" />
      <EventRecordID>4753</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:33:10.0000000Z" />
      <EventRecordID>4752</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:21:15.0000000Z" />
      <EventRecordID>4751</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:02:52.0000000Z" />
      <EventRecordID>4750</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:47:48.0000000Z" />
      <EventRecordID>4749</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:38:09.0000000Z" />
      <EventRecordID>4748</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:46:58.0000000Z" />
      <EventRecordID>4747</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:04:59.0000000Z" />
      <EventRecordID>4746</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:45:17.0000000Z" />
      <EventRecordID>4745</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:35:24.0000000Z" />
      <EventRecordID>4744</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:58:45.0000000Z" />
      <EventRecordID>4743</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:43:48.0000000Z" />
      <EventRecordID>4742</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:15:15.0000000Z" />
      <EventRecordID>4741</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:54:23.0000000Z" />
      <EventRecordID>4740</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:45:25.0000000Z" />
      <EventRecordID>4739</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:19:00.0000000Z" />
      <EventRecordID>4738</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:21:37.0000000Z" />
      <EventRecordID>4737</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:01:59.0000000Z" />
      <EventRecordID>4736</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:19:54.0000000Z" />
      <EventRecordID>4735</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:03:00.0000000Z" />
      <EventRecordID>4734</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:53:42.0000000Z" />
      <EventRecordID>4733</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:23:19.0000000Z" />
      <EventRecordID>4732</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:09:36.0000000Z" />
      <EventRecordID>4731</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:00:07.0000000Z" />
      <EventRecordID>4730</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:19:57.0000000Z" />
      <EventRecordID>4729</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:50:53.0000000Z" />
      <EventRecordID>4728</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:27:56.0000000Z" />
      <EventRecordID>4727</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:09:43.0000000Z" />
      <EventRecordID>4726</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:44:57.0000000Z" />
      <EventRecordID>4725</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:39:14.0000000Z" />
      <EventRecordID>4724</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:35:17.0000000Z" />
      <EventRecordID>4723</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:38:17.0000000Z" />
      <EventRecordID>4722</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:57:44.0000000Z" />
      <EventRecordID>4721</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:14:52.0000000Z" />
      <EventRecordID>4720</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:24:38.0000000Z" />
      <EventRecordID>4719</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:47:37.0000000Z" />
      <EventRecordID>4718</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:19:35.0000000Z" />
      <EventRecordID>4717</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:35:22.0000000Z" />
      <EventRecordID>4716</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:33:00.0000000Z" />
      <EventRecordID>4715</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:54:55.0000000Z" />
      <EventRecordID>4714</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:46:40.0000000Z" />
      <EventRecordID>4713</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:31:25.0000000Z" />
      <EventRecordID>4712</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:09:16.0000000Z" />
      <EventRecordID>4711</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:17:22.0000000Z" />
      <EventRecordID>4710</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:34:46.0000000Z" />
      <EventRecordID>4709</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:30:33.0000000Z" />
      <EventRecordID>4708</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:44:03.0000000Z" />
      <EventRecordID>4707</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:52:49.0000000Z" />
      <EventRecordID>4706</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:36:18.0000000Z" />
      <EventRecordID>4705</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:53:45.0000000Z" />
      <EventRecordID>4704</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:38:50.0000000Z" />
      <EventRecordID>4703</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:21:03.0000000Z" />
      <EventRecordID>4702</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:26:32.0000000Z" />
      <EventRecordID>4701</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:58:08.0000000Z" />
      <EventRecordID>4700</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:21:34.0000000Z" />
      <EventRecordID>4699</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:57:28.0000000Z" />
      <EventRecordID>4698</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:20:11.0000000Z" />
      <EventRecordID>4697</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:18:21.0000000Z" />
      <EventRecordID>4696</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:18:15.0000000Z" />
      <EventRecordID>4695</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:02:45.0000000Z" />
      <EventRecordID>4694</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:34:48.0000000Z" />
      <EventRecordID>4693</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:18:15.0000000Z" />
      <EventRecordID>4692</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:14:31.0000000Z" />
      <EventRecordID>4691</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:43:34.0000000Z" />
      <EventRecordID>4690</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:48:27.0000000Z" />
      <EventRecordID>4689</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:09:59.0000000Z" />
      <EventRecordID>4688</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:22:03.0000000Z" />
      <EventRecordID>4687</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:46:42.0000000Z" />
      <EventRecordID>4686</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:46:30.0000000Z" />
      <EventRecordID>4685</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:21:52.0000000Z" />
      <EventRecordID>4684</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:12:59.0000000Z" />
      <EventRecordID>4683</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:08:31.0000000Z" />
      <EventRecordID>4682</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:50:15.0000000Z" />
      <EventRecordID>4681</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:27:02.0000000Z" />
      <EventRecordID>4680</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:42:59.0000000Z" />
      <EventRecordID>4679</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:36:01.0000000Z" />
      <EventRecordID>4678</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:40:57.0000000Z" />
      <EventRecordID>4677</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:42:23.0000000Z" />
      <EventRecordID>4676</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:32:00.0000000Z" />
      <EventRecordID>4675</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:31:17.0000000Z" />
      <EventRecordID>4674</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:54:38.0000000Z" />
      <EventRecordID>4673</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:37:05.0000000Z" />
      <EventRecordID>4672</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:32:39.0000000Z" />
      <EventRecordID>4671</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:09:12.0000000Z" />
      <EventRecordID>4670</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:17:36.0000000Z" />
      <EventRecordID>4669</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:42:11.0000000Z" />
      <EventRecordID>4668</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:52:09.0000000Z" />
      <EventRecordID>4667</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:01:28.0000000Z" />
      <EventRecordID>4666</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:47:40.0000000Z" />
      <EventRecordID>4665</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:12:36.0000000Z" />
      <EventRecordID>4664</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:05:08.0000000Z" />
      <EventRecordID>4663</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:57:07.0000000Z" />
      <EventRecordID>4662</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:14:03.0000000Z" />
      <EventRecordID>4661</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:56:44.0000000Z" />
      <EventRecordID>4660</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:26:03.0000000Z" />
      <EventRecordID>4659</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:09:16.0000000Z" />
      <EventRecordID>4658</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:34:35.0000000Z" />
      <EventRecordID>4657</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:42:36.0000000Z" />
      <EventRecordID>4656</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:54:44.0000000Z" />
      <EventRecordID>4655</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:29:13.0000000Z" />
      <EventRecordID>4654</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:04:39.0000000Z" />
      <EventRecordID>4653</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:59:13.0000000Z" />
      <EventRecordID>4652</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:42:36.0000000Z" />
      <EventRecordID>4651</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:19:53.0000000Z" />
      <EventRecordID>4650</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:07:05.0000000Z" />
      <EventRecordID>4649</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:04:30.0000000Z" />
      <EventRecordID>4648</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:50:03.0000000Z" />
      <EventRecordID>4647</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:43:04.0000000Z" />
      <EventRecordID>4646</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:24:07.0000000Z" />
      <EventRecordID>4645</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:41:28.0000000Z" />
      <EventRecordID>4644</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:10:55.0000000Z" />
      <EventRecordID>4643</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:48:57.0000000Z" />
      <EventRecordID>4642</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:22:32.0000000Z" />
      <EventRecordID>4641</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:51:47.0000000Z" />
      <EventRecordID>4640</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:35:39.0000000Z" />
      <EventRecordID>4639</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:19:15.0000000Z" />
      <EventRecordID>4638</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:47:59.0000000Z" />
      <EventRecordID>4637</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:36:39.0000000Z" />
      <EventRecordID>4636</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:45:04.0000000Z" />
      <EventRecordID>4635</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:12:05.0000000Z" />
      <EventRecordID>4634</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:19:25.0000000Z" />
      <EventRecordID>4633</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:20:29.0000000Z" />
      <EventRecordID>4632</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:59:08.0000000Z" />
      <EventRecordID>4631</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:32:39.0000000Z" />
      <EventRecordID>4630</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:46:51.0000000Z" />
      <EventRecordID>4629</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:12:37.0000000Z" />
      <EventRecordID>4628</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:03:03.0000000Z" />
      <EventRecordID>4627</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:28:20.0000000Z" />
      <EventRecordID>4626</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:52:39.0000000Z" />
      <EventRecordID>4625</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:02:59.0000000Z" />
      <EventRecordID>4624</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:49:36.0000000Z" />
      <EventRecordID>4623</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:11:03.0000000Z" />
      <EventRecordID>4622</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:42:37.0000000Z" />
      <EventRecordID>4621</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:20:41.0000000Z" />
      <EventRecordID>4620</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:47:20.0000000Z" />
      <EventRecordID>4619</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:33:09.0000000Z" />
      <EventRecordID>4618</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:07:12.0000000Z" />
      <EventRecordID>4617</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:25:56.0000000Z" />
      <EventRecordID>4616</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:25:22.0000000Z" />
      <EventRecordID>4615</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:43:25.0000000Z" />
      <EventRecordID>4614</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:43:36.0000000Z" />
      <EventRecordID>4613</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:56:58.0000000Z" />
      <EventRecordID>4612</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:45:09.0000000Z" />
      <EventRecordID>4611</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:59:25.0000000Z" />
      <EventRecordID>4610</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:10:26.0000000Z" />
      <EventRecordID>4609</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:54:42.0000000Z" />
      <EventRecordID>4608</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:13:25.0000000Z" />
      <EventRecordID>4607</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:14:46.0000000Z" />
      <EventRecordID>4606</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:14:16.0000000Z" />
      <EventRecordID>4605</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:52:25.0000000Z" />
      <EventRecordID>4604</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:25:19.0000000Z" />
      <EventRecordID>4603</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:17:55.0000000Z" />
      <EventRecordID>4602</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:28:28.0000000Z" />
      <EventRecordID>4601</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:38:44.0000000Z" />
      <EventRecordID>4600</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:41:30.0000000Z" />
      <EventRecordID>4599</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:26:11.0000000Z" />
      <EventRecordID>4598</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:59:19.0000000Z" />
      <EventRecordID>4597</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:44:26.0000000Z" />
      <EventRecordID>4596</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:37:56.0000000Z" />
      <EventRecordID>4595</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:27:43.0000000Z" />
      <EventRecordID>4594</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:39:41.0000000Z" />
      <EventRecordID>4593</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:57:45.0000000Z" />
      <EventRecordID>4592</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:44:45.0000000Z" />
      <EventRecordID>4591</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:38:21.0000000Z" />
      <EventRecordID>4590</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:30:02.0000000Z" />
      <EventRecordID>4589</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:22:53.0000000Z" />
      <EventRecordID>4588</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:03:32.0000000Z" />
      <EventRecordID>4587</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:33:49.0000000Z" />
      <EventRecordID>4586</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:21:20.0000000Z" />
      <EventRecordID>4585</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:20:59.0000000Z" />
      <EventRecordID>4584</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:30:12.0000000Z" />
      <EventRecordID>4583</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:26:20.0000000Z" />
      <EventRecordID>4582</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:42:07.0000000Z" />
      <EventRecordID>4581</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:26:45.0000000Z" />
      <EventRecordID>4580</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:15:10.0000000Z" />
      <EventRecordID>4579</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:58:42.0000000Z" />
      <EventRecordID>4578</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:49:16.0000000Z" />
      <EventRecordID>4577</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:59:41.0000000Z" />
      <EventRecordID>4576</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:04:30.0000000Z" />
      <EventRecordID>4575</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:38:25.0000000Z" />
      <EventRecordID>4574</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:46:37.0000000Z" />
      <EventRecordID>4573</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:08:40.0000000Z" />
      <EventRecordID>4572</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:14:02.0000000Z" />
      <EventRecordID>4571</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:57:02.0000000Z" />
      <EventRecordID>4570</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:25:00.0000000Z" />
      <EventRecordID>4569</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:40:02.0000000Z" />
      <EventRecordID>4568</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:16:34.0000000Z" />
      <EventRecordID>4567</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:38:13.0000000Z" />
      <EventRecordID>4566</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:15:07.0000000Z" />
      <EventRecordID>4565</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:33:45.0000000Z" />
      <EventRecordID>4564</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:56:46.0000000Z" />
      <EventRecordID>4563</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:03:10.0000000Z" />
      <EventRecordID>4562</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:40:19.0000000Z" />
      <EventRecordID>4561</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:46:59.0000000Z" />
      <EventRecordID>4560</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:43:32.0000000Z" />
      <EventRecordID>4559</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:52:39.0000000Z" />
      <EventRecordID>4558</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:32:24.0000000Z" />
      <EventRecordID>4557</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:50:02.0000000Z" />
      <EventRecordID>4556</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:06:14.0000000Z" />
      <EventRecordID>4555</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:23:03.0000000Z" />
      <EventRecordID>4554</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:40:22.0000000Z" />
      <EventRecordID>4553</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:01:58.0000000Z" />
      <EventRecordID>4552</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:56:57.0000000Z" />
      <EventRecordID>4551</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:26:47.0000000Z" />
      <EventRecordID>4550</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:33:52.0000000Z" />
      <EventRecordID>4549</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:23:19.0000000Z" />
      <EventRecordID>4548</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:10:43.0000000Z" />
      <EventRecordID>4547</EventRecordID>
      <Correlation />
      <Execution ProcessID="3668" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:54Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:57:29.0000000Z" />
      <EventRecordID>4546</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:42:25.0000000Z" />
      <EventRecordID>4545</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:38:20.0000000Z" />
      <EventRecordID>4544</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:10:12.0000000Z" />
      <EventRecordID>4543</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:21:56.0000000Z" />
      <EventRecordID>4542</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:14:01.0000000Z" />
      <EventRecordID>4541</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:09:29.0000000Z" />
      <EventRecordID>4540</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:01:05.0000000Z" />
      <EventRecordID>4539</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:58:00.0000000Z" />
      <EventRecordID>4538</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:53:33.0000000Z" />
      <EventRecordID>4537</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:19:18.0000000Z" />
      <EventRecordID>4536</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:37:24.0000000Z" />
      <EventRecordID>4535</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:03:02.0000000Z" />
      <EventRecordID>4534</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:02:50.0000000Z" />
      <EventRecordID>4533</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:08:48.0000000Z" />
      <EventRecordID>4532</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:09:34.0000000Z" />
      <EventRecordID>4531</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:54:29.0000000Z" />
      <EventRecordID>4530</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:58:59.0000000Z" />
      <EventRecordID>4529</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:15:08.0000000Z" />
      <EventRecordID>4528</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:13:32.0000000Z" />
      <EventRecordID>4527</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:37:34.0000000Z" />
      <EventRecordID>4526</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:16:59.0000000Z" />
      <EventRecordID>4525</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:13:09.0000000Z" />
      <EventRecordID>4524</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:03:19.0000000Z" />
      <EventRecordID>4523</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:42:22.0000000Z" />
      <EventRecordID>4522</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:13:21.0000000Z" />
      <EventRecordID>4521</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:26:20.0000000Z" />
      <EventRecordID>4520</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:39:21.0000000Z" />
      <EventRecordID>4519</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:29:35.0000000Z" />
      <EventRecordID>4518</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:29:29.0000000Z" />
      <EventRecordID>4517</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:49:41.0000000Z" />
      <EventRecordID>4516</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:14:26.0000000Z" />
      <EventRecordID>4515</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:20:05.0000000Z" />
      <EventRecordID>4514</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:04:19.0000000Z" />
      <EventRecordID>4513</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:20:27.0000000Z" />
      <EventRecordID>4512</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:47:45.0000000Z" />
      <EventRecordID>4511</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:52:21.0000000Z" />
      <EventRecordID>4510</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:08:37.0000000Z" />
      <EventRecordID>4509</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:54:58.0000000Z" />
      <EventRecordID>4508</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:14:01.0000000Z" />
      <EventRecordID>4507</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:42:13.0000000Z" />
      <EventRecordID>4506</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:01:17.0000000Z" />
      <EventRecordID>4505</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:46:15.0000000Z" />
      <EventRecordID>4504</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:31:03.0000000Z" />
      <EventRecordID>4503</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:17:24.0000000Z" />
      <EventRecordID>4502</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:47:57.0000000Z" />
      <EventRecordID>4501</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:54:53.0000000Z" />
      <EventRecordID>4500</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:12:05.0000000Z" />
      <EventRecordID>4499</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:23:23.0000000Z" />
      <EventRecordID>4498</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:33:12.0000000Z" />
      <EventRecordID>4497</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:47:38.0000000Z" />
      <EventRecordID>4496</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:20:12.0000000Z" />
      <EventRecordID>4495</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:38:25.0000000Z" />
      <EventRecordID>4494</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:17:56.0000000Z" />
      <EventRecordID>4493</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:45:57.0000000Z" />
      <EventRecordID>4492</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:51:30.0000000Z" />
      <EventRecordID>4491</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:14:11.0000000Z" />
      <EventRecordID>4490</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:12:07.0000000Z" />
      <EventRecordID>4489</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:51:32.0000000Z" />
      <EventRecordID>4488</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:23:20.0000000Z" />
      <EventRecordID>4487</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:07:09.0000000Z" />
      <EventRecordID>4486</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:29:07.0000000Z" />
      <EventRecordID>4485</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:11:05.0000000Z" />
      <EventRecordID>4484</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:18:50.0000000Z" />
      <EventRecordID>4483</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:54:46.0000000Z" />
      <EventRecordID>4482</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:29:22.0000000Z" />
      <EventRecordID>4481</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:20:09.0000000Z" />
      <EventRecordID>4480</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:58:48.0000000Z" />
      <EventRecordID>4479</EventRecordID>
      <Correlation />
      <Execution ProcessID="3668" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:52:10.0000000Z" />
      <EventRecordID>4478</EventRecordID>
      <Correlation />
      <Execution ProcessID="1720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:56Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:14:12.0000000Z" />
      <EventRecordID>4477</EventRecordID>
      <Correlation />
      <Execution ProcessID="1720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:15:58.0000000Z" />
      <EventRecordID>4476</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:59:30.0000000Z" />
      <EventRecordID>4475</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:07:00.0000000Z" />
      <EventRecordID>4474</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:03:08.0000000Z" />
      <EventRecordID>4473</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:12:16.0000000Z" />
      <EventRecordID>4472</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:26:34.0000000Z" />
      <EventRecordID>4471</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:00:06.0000000Z" />
      <EventRecordID>4470</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:07:59.0000000Z" />
      <EventRecordID>4469</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:44:53.0000000Z" />
      <EventRecordID>4468</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:23:19.0000000Z" />
      <EventRecordID>4467</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:16:39.0000000Z" />
      <EventRecordID>4466</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:17:33.0000000Z" />
      <EventRecordID>4465</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:16:30.0000000Z" />
      <EventRecordID>4464</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:32:20.0000000Z" />
      <EventRecordID>4463</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:18:17.0000000Z" />
      <EventRecordID>4462</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:41:51.0000000Z" />
      <EventRecordID>4461</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:12:45.0000000Z" />
      <EventRecordID>4460</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:41:14.0000000Z" />
      <EventRecordID>4459</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:38:16.0000000Z" />
      <EventRecordID>4458</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:24:52.0000000Z" />
      <EventRecordID>4457</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:01:41.0000000Z" />
      <EventRecordID>4456</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:45:02.0000000Z" />
      <EventRecordID>4455</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:07:00.0000000Z" />
      <EventRecordID>4454</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:22:41.0000000Z" />
      <EventRecordID>4453</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:36:57.0000000Z" />
      <EventRecordID>4452</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:58:58.0000000Z" />
      <EventRecordID>4451</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:34:25.0000000Z" />
      <EventRecordID>4450</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:40:12.0000000Z" />
      <EventRecordID>4449</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:57:49.0000000Z" />
      <EventRecordID>4448</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:51:14.0000000Z" />
      <EventRecordID>4447</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:38:16.0000000Z" />
      <EventRecordID>4446</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:58:44.0000000Z" />
      <EventRecordID>4445</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:40:27.0000000Z" />
      <EventRecordID>4444</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:42:03.0000000Z" />
      <EventRecordID>4443</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:07:23.0000000Z" />
      <EventRecordID>4442</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:27:47.0000000Z" />
      <EventRecordID>4441</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:41:48.0000000Z" />
      <EventRecordID>4440</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:49:11.0000000Z" />
      <EventRecordID>4439</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:18:08.0000000Z" />
      <EventRecordID>4438</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:55:17.0000000Z" />
      <EventRecordID>4437</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:15:32.0000000Z" />
      <EventRecordID>4436</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:53:50.0000000Z" />
      <EventRecordID>4435</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:27:22.0000000Z" />
      <EventRecordID>4434</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:01:22.0000000Z" />
      <EventRecordID>4433</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:27:42.0000000Z" />
      <EventRecordID>4432</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:22:58.0000000Z" />
      <EventRecordID>4431</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:30:45.0000000Z" />
      <EventRecordID>4430</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:23:17.0000000Z" />
      <EventRecordID>4429</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:25:54.0000000Z" />
      <EventRecordID>4428</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:09:48.0000000Z" />
      <EventRecordID>4427</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:25:28.0000000Z" />
      <EventRecordID>4426</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:02:17.0000000Z" />
      <EventRecordID>4425</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:27:36.0000000Z" />
      <EventRecordID>4424</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:12:52.0000000Z" />
      <EventRecordID>4423</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:01:05.0000000Z" />
      <EventRecordID>4422</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:07:27.0000000Z" />
      <EventRecordID>4421</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:58:04.0000000Z" />
      <EventRecordID>4420</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:59:12.0000000Z" />
      <EventRecordID>4419</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:41:07.0000000Z" />
      <EventRecordID>4418</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:17:03.0000000Z" />
      <EventRecordID>4417</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:47:19.0000000Z" />
      <EventRecordID>4416</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:52:15.0000000Z" />
      <EventRecordID>4415</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:20:03.0000000Z" />
      <EventRecordID>4414</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:43:28.0000000Z" />
      <EventRecordID>4413</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:52:41.0000000Z" />
      <EventRecordID>4412</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:19:08.0000000Z" />
      <EventRecordID>4411</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:17:20.0000000Z" />
      <EventRecordID>4410</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:36:55.0000000Z" />
      <EventRecordID>4409</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:59:08.0000000Z" />
      <EventRecordID>4408</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:41:17.0000000Z" />
      <EventRecordID>4407</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:58:12.0000000Z" />
      <EventRecordID>4406</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:28:00.0000000Z" />
      <EventRecordID>4405</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:18:22.0000000Z" />
      <EventRecordID>4404</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:12:36.0000000Z" />
      <EventRecordID>4403</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:40:28.0000000Z" />
      <EventRecordID>4402</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:23:51.0000000Z" />
      <EventRecordID>4401</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:17:36.0000000Z" />
      <EventRecordID>4400</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:41:18.0000000Z" />
      <EventRecordID>4399</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:06:46.0000000Z" />
      <EventRecordID>4398</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:45:03.0000000Z" />
      <EventRecordID>4397</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:31:37.0000000Z" />
      <EventRecordID>4396</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:00:14.0000000Z" />
      <EventRecordID>4395</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:49:51.0000000Z" />
      <EventRecordID>4394</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:43:06.0000000Z" />
      <EventRecordID>4393</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:56:31.0000000Z" />
      <EventRecordID>4392</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:50:45.0000000Z" />
      <EventRecordID>4391</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:28:17.0000000Z" />
      <EventRecordID>4390</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:24:20.0000000Z" />
      <EventRecordID>4389</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:06:01.0000000Z" />
      <EventRecordID>4388</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:44:08.0000000Z" />
      <EventRecordID>4387</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:53:22.0000000Z" />
      <EventRecordID>4386</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:55:22.0000000Z" />
      <EventRecordID>4385</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:21:48.0000000Z" />
      <EventRecordID>4384</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:28:43.0000000Z" />
      <EventRecordID>4383</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:14:43.0000000Z" />
      <EventRecordID>4382</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:56:04.0000000Z" />
      <EventRecordID>4381</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:49:11.0000000Z" />
      <EventRecordID>4380</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:38:16.0000000Z" />
      <EventRecordID>4379</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:08:57.0000000Z" />
      <EventRecordID>4378</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:07:17.0000000Z" />
      <EventRecordID>4377</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:07:25.0000000Z" />
      <EventRecordID>4376</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:10:19.0000000Z" />
      <EventRecordID>4375</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:57:53.0000000Z" />
      <EventRecordID>4374</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:14:29.0000000Z" />
      <EventRecordID>4373</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:52:06.0000000Z" />
      <EventRecordID>4372</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:29:53.0000000Z" />
      <EventRecordID>4371</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:02:40.0000000Z" />
      <EventRecordID>4370</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:20:42.0000000Z" />
      <EventRecordID>4369</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:19:05.0000000Z" />
      <EventRecordID>4368</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:11:12.0000000Z" />
      <EventRecordID>4367</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:11:56.0000000Z" />
      <EventRecordID>4366</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:28:43.0000000Z" />
      <EventRecordID>4365</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:39:46.0000000Z" />
      <EventRecordID>4364</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:31:09.0000000Z" />
      <EventRecordID>4363</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:43:22.0000000Z" />
      <EventRecordID>4362</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:46:57.0000000Z" />
      <EventRecordID>4361</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:03:07.0000000Z" />
      <EventRecordID>4360</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:12:34.0000000Z" />
      <EventRecordID>4359</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:07:40.0000000Z" />
      <EventRecordID>4358</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:22:32.0000000Z" />
      <EventRecordID>4357</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:04:50.0000000Z" />
      <EventRecordID>4356</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:55:19.0000000Z" />
      <EventRecordID>4355</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:18:36.0000000Z" />
      <EventRecordID>4354</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:12:22.0000000Z" />
      <EventRecordID>4353</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:05:10.0000000Z" />
      <EventRecordID>4352</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:34:23.0000000Z" />
      <EventRecordID>4351</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:22:35.0000000Z" />
      <EventRecordID>4350</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:54:20.0000000Z" />
      <EventRecordID>4349</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:20:51.0000000Z" />
      <EventRecordID>4348</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:03:14.0000000Z" />
      <EventRecordID>4347</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:12:42.0000000Z" />
      <EventRecordID>4346</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:53:22.0000000Z" />
      <EventRecordID>4345</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:21:47.0000000Z" />
      <EventRecordID>4344</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:30:53.0000000Z" />
      <EventRecordID>4343</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:52:34.0000000Z" />
      <EventRecordID>4342</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:15:55.0000000Z" />
      <EventRecordID>4341</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:27:33.0000000Z" />
      <EventRecordID>4340</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:03:19.0000000Z" />
      <EventRecordID>4339</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:06:02.0000000Z" />
      <EventRecordID>4338</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:12:55.0000000Z" />
      <EventRecordID>4337</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:02:00.0000000Z" />
      <EventRecordID>4336</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:46:15.0000000Z" />
      <EventRecordID>4335</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:04:20.0000000Z" />
      <EventRecordID>4334</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:22:21.0000000Z" />
      <EventRecordID>4333</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:10:05.0000000Z" />
      <EventRecordID>4332</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:03:59.0000000Z" />
      <EventRecordID>4331</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:35:14.0000000Z" />
      <EventRecordID>4330</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:47:14.0000000Z" />
      <EventRecordID>4329</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:27:39.0000000Z" />
      <EventRecordID>4328</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:16:25.0000000Z" />
      <EventRecordID>4327</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:54:31.0000000Z" />
      <EventRecordID>4326</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:53:17.0000000Z" />
      <EventRecordID>4325</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:07:02.0000000Z" />
      <EventRecordID>4324</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:21:33.0000000Z" />
      <EventRecordID>4323</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:41:22.0000000Z" />
      <EventRecordID>4322</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:59:07.0000000Z" />
      <EventRecordID>4321</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:08:23.0000000Z" />
      <EventRecordID>4320</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:27:08.0000000Z" />
      <EventRecordID>4319</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:57:03.0000000Z" />
      <EventRecordID>4318</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:10:46.0000000Z" />
      <EventRecordID>4317</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:54:04.0000000Z" />
      <EventRecordID>4316</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:41:19.0000000Z" />
      <EventRecordID>4315</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:46:27.0000000Z" />
      <EventRecordID>4314</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:19:34.0000000Z" />
      <EventRecordID>4313</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:28:30.0000000Z" />
      <EventRecordID>4312</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:53:59.0000000Z" />
      <EventRecordID>4311</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:10:28.0000000Z" />
      <EventRecordID>4310</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:37:45.0000000Z" />
      <EventRecordID>4309</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:18:01.0000000Z" />
      <EventRecordID>4308</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:16:45.0000000Z" />
      <EventRecordID>4307</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:08:32.0000000Z" />
      <EventRecordID>4306</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:30:23.0000000Z" />
      <EventRecordID>4305</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:25:49.0000000Z" />
      <EventRecordID>4304</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:58:22.0000000Z" />
      <EventRecordID>4303</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:34:55.0000000Z" />
      <EventRecordID>4302</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:02:55.0000000Z" />
      <EventRecordID>4301</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:13:46.0000000Z" />
      <EventRecordID>4300</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:46:19.0000000Z" />
      <EventRecordID>4299</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:50:04.0000000Z" />
      <EventRecordID>4298</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:16:39.0000000Z" />
      <EventRecordID>4297</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:57:37.0000000Z" />
      <EventRecordID>4296</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:06:25.0000000Z" />
      <EventRecordID>4295</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:09:00.0000000Z" />
      <EventRecordID>4294</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:31:23.0000000Z" />
      <EventRecordID>4293</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:55:50.0000000Z" />
      <EventRecordID>4292</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:35:15.0000000Z" />
      <EventRecordID>4291</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:22:06.0000000Z" />
      <EventRecordID>4290</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:11:18.0000000Z" />
      <EventRecordID>4289</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:25:31.0000000Z" />
      <EventRecordID>4288</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:40:42.0000000Z" />
      <EventRecordID>4287</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:47:37.0000000Z" />
      <EventRecordID>4286</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:45:27.0000000Z" />
      <EventRecordID>4285</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:29:18.0000000Z" />
      <EventRecordID>4284</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:34:40.0000000Z" />
      <EventRecordID>4283</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:36:55.0000000Z" />
      <EventRecordID>4282</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:35:46.0000000Z" />
      <EventRecordID>4281</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:19:05.0000000Z" />
      <EventRecordID>4280</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:12:06.0000000Z" />
      <EventRecordID>4279</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:03:54.0000000Z" />
      <EventRecordID>4278</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:09:13.0000000Z" />
      <EventRecordID>4277</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:18:34.0000000Z" />
      <EventRecordID>4276</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:53:32.0000000Z" />
      <EventRecordID>4275</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:50:46.0000000Z" />
      <EventRecordID>4274</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:48:27.0000000Z" />
      <EventRecordID>4273</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:29:37.0000000Z" />
      <EventRecordID>4272</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:41:53.0000000Z" />
      <EventRecordID>4271</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:35:17.0000000Z" />
      <EventRecordID>4270</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:38:05.0000000Z" />
      <EventRecordID>4269</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:17:30.0000000Z" />
      <EventRecordID>4268</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:38:34.0000000Z" />
      <EventRecordID>4267</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:04:23.0000000Z" />
      <EventRecordID>4266</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:17:15.0000000Z" />
      <EventRecordID>4265</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:56:59.0000000Z" />
      <EventRecordID>4264</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:53:38.0000000Z" />
      <EventRecordID>4263</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:45:39.0000000Z" />
      <EventRecordID>4262</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:39:13.0000000Z" />
      <EventRecordID>4261</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:57:52.0000000Z" />
      <EventRecordID>4260</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:57:40.0000000Z" />
      <EventRecordID>4259</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:07:29.0000000Z" />
      <EventRecordID>4258</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:46:07.0000000Z" />
      <EventRecordID>4257</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:09:11.0000000Z" />
      <EventRecordID>4256</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:54:21.0000000Z" />
      <EventRecordID>4255</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:23:37.0000000Z" />
      <EventRecordID>4254</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:48:05.0000000Z" />
      <EventRecordID>4253</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:17:28.0000000Z" />
      <EventRecordID>4252</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:24:37.0000000Z" />
      <EventRecordID>4251</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:32:22.0000000Z" />
      <EventRecordID>4250</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:26:37.0000000Z" />
      <EventRecordID>4249</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:29:40.0000000Z" />
      <EventRecordID>4248</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:13:41.0000000Z" />
      <EventRecordID>4247</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:10:19.0000000Z" />
      <EventRecordID>4246</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:49:48.0000000Z" />
      <EventRecordID>4245</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:52:24.0000000Z" />
      <EventRecordID>4244</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:57:07.0000000Z" />
      <EventRecordID>4243</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:11:30.0000000Z" />
      <EventRecordID>4242</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:30:33.0000000Z" />
      <EventRecordID>4241</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:14:55.0000000Z" />
      <EventRecordID>4240</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:36:14.0000000Z" />
      <EventRecordID>4239</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:20:07.0000000Z" />
      <EventRecordID>4238</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:51:05.0000000Z" />
      <EventRecordID>4237</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:30:58.0000000Z" />
      <EventRecordID>4236</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:46:10.0000000Z" />
      <EventRecordID>4235</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:36:01.0000000Z" />
      <EventRecordID>4234</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:52:46.0000000Z" />
      <EventRecordID>4233</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:38:15.0000000Z" />
      <EventRecordID>4232</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:05:26.0000000Z" />
      <EventRecordID>4231</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:43:38.0000000Z" />
      <EventRecordID>4230</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:31:46.0000000Z" />
      <EventRecordID>4229</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:38:47.0000000Z" />
      <EventRecordID>4228</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:58:44.0000000Z" />
      <EventRecordID>4227</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:18:08.0000000Z" />
      <EventRecordID>4226</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:40:27.0000000Z" />
      <EventRecordID>4225</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:29:05.0000000Z" />
      <EventRecordID>4224</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:02:18.0000000Z" />
      <EventRecordID>4223</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:30:10.0000000Z" />
      <EventRecordID>4222</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:18:45.0000000Z" />
      <EventRecordID>4221</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:03:02.0000000Z" />
      <EventRecordID>4220</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:00:56.0000000Z" />
      <EventRecordID>4219</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:41:22.0000000Z" />
      <EventRecordID>4218</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:08:53.0000000Z" />
      <EventRecordID>4217</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:58:30.0000000Z" />
      <EventRecordID>4216</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:49:00.0000000Z" />
      <EventRecordID>4215</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:16:51.0000000Z" />
      <EventRecordID>4214</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:43:30.0000000Z" />
      <EventRecordID>4213</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:46:46.0000000Z" />
      <EventRecordID>4212</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:23:58.0000000Z" />
      <EventRecordID>4211</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:05:01.0000000Z" />
      <EventRecordID>4210</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:37:50.0000000Z" />
      <EventRecordID>4209</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:40:52.0000000Z" />
      <EventRecordID>4208</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:34:09.0000000Z" />
      <EventRecordID>4207</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:54:11.0000000Z" />
      <EventRecordID>4206</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:32:20.0000000Z" />
      <EventRecordID>4205</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:43:44.0000000Z" />
      <EventRecordID>4204</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:51:44.0000000Z" />
      <EventRecordID>4203</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:58:34.0000000Z" />
      <EventRecordID>4202</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:04:36.0000000Z" />
      <EventRecordID>4201</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:28:12.0000000Z" />
      <EventRecordID>4200</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:41:42.0000000Z" />
      <EventRecordID>4199</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:33:57.0000000Z" />
      <EventRecordID>4198</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:14:00.0000000Z" />
      <EventRecordID>4197</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:27:34.0000000Z" />
      <EventRecordID>4196</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:38:15.0000000Z" />
      <EventRecordID>4195</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:51:45.0000000Z" />
      <EventRecordID>4194</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:30:54.0000000Z" />
      <EventRecordID>4193</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:16:31.0000000Z" />
      <EventRecordID>4192</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:21:33.0000000Z" />
      <EventRecordID>4191</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:57:09.0000000Z" />
      <EventRecordID>4190</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:40:33.0000000Z" />
      <EventRecordID>4189</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:49:57.0000000Z" />
      <EventRecordID>4188</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:31:02.0000000Z" />
      <EventRecordID>4187</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:50:18.0000000Z" />
      <EventRecordID>4186</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:19:01.0000000Z" />
      <EventRecordID>4185</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:20:49.0000000Z" />
      <EventRecordID>4184</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:17:47.0000000Z" />
      <EventRecordID>4183</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:34:48.0000000Z" />
      <EventRecordID>4182</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:15:31.0000000Z" />
      <EventRecordID>4181</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:57:41.0000000Z" />
      <EventRecordID>4180</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:13:58.0000000Z" />
      <EventRecordID>4179</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:39:18.0000000Z" />
      <EventRecordID>4178</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:33:21.0000000Z" />
      <EventRecordID>4177</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:09:13.0000000Z" />
      <EventRecordID>4176</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:18:42.0000000Z" />
      <EventRecordID>4175</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:37:00.0000000Z" />
      <EventRecordID>4174</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:20:32.0000000Z" />
      <EventRecordID>4173</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:29:25.0000000Z" />
      <EventRecordID>4172</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:19:04.0000000Z" />
      <EventRecordID>4171</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:57:15.0000000Z" />
      <EventRecordID>4170</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:23:51.0000000Z" />
      <EventRecordID>4169</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:51:29.0000000Z" />
      <EventRecordID>4168</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:46:15.0000000Z" />
      <EventRecordID>4167</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:33:30.0000000Z" />
      <EventRecordID>4166</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:54:35.0000000Z" />
      <EventRecordID>4165</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:15:14.0000000Z" />
      <EventRecordID>4164</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:16:32.0000000Z" />
      <EventRecordID>4163</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:01:00.0000000Z" />
      <EventRecordID>4162</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:42:28.0000000Z" />
      <EventRecordID>4161</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:25:13.0000000Z" />
      <EventRecordID>4160</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:50:44.0000000Z" />
      <EventRecordID>4159</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:36:34.0000000Z" />
      <EventRecordID>4158</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:10:21.0000000Z" />
      <EventRecordID>4157</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:23:28.0000000Z" />
      <EventRecordID>4156</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:26:48.0000000Z" />
      <EventRecordID>4155</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:04:11.0000000Z" />
      <EventRecordID>4154</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:40:21.0000000Z" />
      <EventRecordID>4153</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:08:12.0000000Z" />
      <EventRecordID>4152</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:21:30.0000000Z" />
      <EventRecordID>4151</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:49:02.0000000Z" />
      <EventRecordID>4150</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:43:32.0000000Z" />
      <EventRecordID>4149</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:18:31.0000000Z" />
      <EventRecordID>4148</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:53:46.0000000Z" />
      <EventRecordID>4147</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:09:24.0000000Z" />
      <EventRecordID>4146</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:06:38.0000000Z" />
      <EventRecordID>4145</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:45:11.0000000Z" />
      <EventRecordID>4144</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:30:00.0000000Z" />
      <EventRecordID>4143</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:45:06.0000000Z" />
      <EventRecordID>4142</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:26:19.0000000Z" />
      <EventRecordID>4141</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:59:49.0000000Z" />
      <EventRecordID>4140</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:01:53.0000000Z" />
      <EventRecordID>4139</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:38:55.0000000Z" />
      <EventRecordID>4138</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:57:11.0000000Z" />
      <EventRecordID>4137</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:23:22.0000000Z" />
      <EventRecordID>4136</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:35:43.0000000Z" />
      <EventRecordID>4135</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:02:44.0000000Z" />
      <EventRecordID>4134</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:07:08.0000000Z" />
      <EventRecordID>4133</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:44:54.0000000Z" />
      <EventRecordID>4132</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:15:18.0000000Z" />
      <EventRecordID>4131</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:37:18.0000000Z" />
      <EventRecordID>4130</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:34:45.0000000Z" />
      <EventRecordID>4129</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:12:41.0000000Z" />
      <EventRecordID>4128</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:50:05.0000000Z" />
      <EventRecordID>4127</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:06:06.0000000Z" />
      <EventRecordID>4126</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:54:35.0000000Z" />
      <EventRecordID>4125</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:06:39.0000000Z" />
      <EventRecordID>4124</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:39:03.0000000Z" />
      <EventRecordID>4123</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:41:26.0000000Z" />
      <EventRecordID>4122</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:12:07.0000000Z" />
      <EventRecordID>4121</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:29:48.0000000Z" />
      <EventRecordID>4120</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:08:57.0000000Z" />
      <EventRecordID>4119</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:50:41.0000000Z" />
      <EventRecordID>4118</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:55:18.0000000Z" />
      <EventRecordID>4117</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:09:27.0000000Z" />
      <EventRecordID>4116</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:04:52.0000000Z" />
      <EventRecordID>4115</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:28:36.0000000Z" />
      <EventRecordID>4114</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:45:35.0000000Z" />
      <EventRecordID>4113</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:00:30.0000000Z" />
      <EventRecordID>4112</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:35:41.0000000Z" />
      <EventRecordID>4111</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:53:31.0000000Z" />
      <EventRecordID>4110</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:47:26.0000000Z" />
      <EventRecordID>4109</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:52:52.0000000Z" />
      <EventRecordID>4108</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:00:46.0000000Z" />
      <EventRecordID>4107</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:04:35.0000000Z" />
      <EventRecordID>4106</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:40:27.0000000Z" />
      <EventRecordID>4105</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:59:13.0000000Z" />
      <EventRecordID>4104</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:02:25.0000000Z" />
      <EventRecordID>4103</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:59:47.0000000Z" />
      <EventRecordID>4102</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:48:54.0000000Z" />
      <EventRecordID>4101</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:06:42.0000000Z" />
      <EventRecordID>4100</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:33:42.0000000Z" />
      <EventRecordID>4099</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:29:46.0000000Z" />
      <EventRecordID>4098</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:05:57.0000000Z" />
      <EventRecordID>4097</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:02:50.0000000Z" />
      <EventRecordID>4096</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:28:21.0000000Z" />
      <EventRecordID>4095</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:15:23.0000000Z" />
      <EventRecordID>4094</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:39:00.0000000Z" />
      <EventRecordID>4093</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:40:33.0000000Z" />
      <EventRecordID>4092</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:28:38.0000000Z" />
      <EventRecordID>4091</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:39:23.0000000Z" />
      <EventRecordID>4090</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:02:36.0000000Z" />
      <EventRecordID>4089</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:30:40.0000000Z" />
      <EventRecordID>4088</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:39:00.0000000Z" />
      <EventRecordID>4087</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:38:17.0000000Z" />
      <EventRecordID>4086</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:51:33.0000000Z" />
      <EventRecordID>4085</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:19:54.0000000Z" />
      <EventRecordID>4084</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:33:14.0000000Z" />
      <EventRecordID>4083</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:46:14.0000000Z" />
      <EventRecordID>4082</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:02:51.0000000Z" />
      <EventRecordID>4081</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:57:25.0000000Z" />
      <EventRecordID>4080</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:18:26.0000000Z" />
      <EventRecordID>4079</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:26:11.0000000Z" />
      <EventRecordID>4078</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>billie.eilish logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:15:58.0000000Z" />
      <EventRecordID>4077</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:31:18.0000000Z" />
      <EventRecordID>4076</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:03:03.0000000Z" />
      <EventRecordID>4075</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:29:34.0000000Z" />
      <EventRecordID>4074</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:21:16.0000000Z" />
      <EventRecordID>4073</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:41:47.0000000Z" />
      <EventRecordID>4072</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:19:19.0000000Z" />
      <EventRecordID>4071</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:08:32.0000000Z" />
      <EventRecordID>4070</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:01:17.0000000Z" />
      <EventRecordID>4069</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:17:06.0000000Z" />
      <EventRecordID>4068</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:41:43.0000000Z" />
      <EventRecordID>4067</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:56:38.0000000Z" />
      <EventRecordID>4066</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:42:45.0000000Z" />
      <EventRecordID>4065</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:41:16.0000000Z" />
      <EventRecordID>4064</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:36:15.0000000Z" />
      <EventRecordID>4063</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:17:09.0000000Z" />
      <EventRecordID>4062</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:22:03.0000000Z" />
      <EventRecordID>4061</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:36:39.0000000Z" />
      <EventRecordID>4060</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:23:37.0000000Z" />
      <EventRecordID>4059</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:37:33.0000000Z" />
      <EventRecordID>4058</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:15:04.0000000Z" />
      <EventRecordID>4057</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:05:41.0000000Z" />
      <EventRecordID>4056</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:38:11.0000000Z" />
      <EventRecordID>4055</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:00:10.0000000Z" />
      <EventRecordID>4054</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:37:26.0000000Z" />
      <EventRecordID>4053</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:19:00.0000000Z" />
      <EventRecordID>4052</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:25:28.0000000Z" />
      <EventRecordID>4051</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:06:33.0000000Z" />
      <EventRecordID>4050</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:30:20.0000000Z" />
      <EventRecordID>4049</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:32:58.0000000Z" />
      <EventRecordID>4048</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:20:23.0000000Z" />
      <EventRecordID>4047</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:36:54.0000000Z" />
      <EventRecordID>4046</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:53:40.0000000Z" />
      <EventRecordID>4045</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:25:24.0000000Z" />
      <EventRecordID>4044</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:32:20.0000000Z" />
      <EventRecordID>4043</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:05:29.0000000Z" />
      <EventRecordID>4042</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:29:16.0000000Z" />
      <EventRecordID>4041</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:34:23.0000000Z" />
      <EventRecordID>4040</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:37:51.0000000Z" />
      <EventRecordID>4039</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:15:20.0000000Z" />
      <EventRecordID>4038</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:05:06.0000000Z" />
      <EventRecordID>4037</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:18:11.0000000Z" />
      <EventRecordID>4036</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:33:32.0000000Z" />
      <EventRecordID>4035</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:24:38.0000000Z" />
      <EventRecordID>4034</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:09:57.0000000Z" />
      <EventRecordID>4033</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:43:05.0000000Z" />
      <EventRecordID>4032</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:48:30.0000000Z" />
      <EventRecordID>4031</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:30:08.0000000Z" />
      <EventRecordID>4030</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:23:48.0000000Z" />
      <EventRecordID>4029</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:51:05.0000000Z" />
      <EventRecordID>4028</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:04:33.0000000Z" />
      <EventRecordID>4027</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:16:10.0000000Z" />
      <EventRecordID>4026</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:44:00.0000000Z" />
      <EventRecordID>4025</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:08:42.0000000Z" />
      <EventRecordID>4024</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:16:47.0000000Z" />
      <EventRecordID>4023</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:43:15.0000000Z" />
      <EventRecordID>4022</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:06:15.0000000Z" />
      <EventRecordID>4021</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:15:20.0000000Z" />
      <EventRecordID>4020</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:20:24.0000000Z" />
      <EventRecordID>4019</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:21:06.0000000Z" />
      <EventRecordID>4018</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:01:18.0000000Z" />
      <EventRecordID>4017</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:16:23.0000000Z" />
      <EventRecordID>4016</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:36:39.0000000Z" />
      <EventRecordID>4015</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:56:19.0000000Z" />
      <EventRecordID>4014</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:13:34.0000000Z" />
      <EventRecordID>4013</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:03:59.0000000Z" />
      <EventRecordID>4012</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:07:57.0000000Z" />
      <EventRecordID>4011</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:08:02.0000000Z" />
      <EventRecordID>4010</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:06:12.0000000Z" />
      <EventRecordID>4009</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:48:58.0000000Z" />
      <EventRecordID>4008</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:30:03.0000000Z" />
      <EventRecordID>4007</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:57:13.0000000Z" />
      <EventRecordID>4006</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:32:33.0000000Z" />
      <EventRecordID>4005</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:57:57.0000000Z" />
      <EventRecordID>4004</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:29:58.0000000Z" />
      <EventRecordID>4003</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:07:03.0000000Z" />
      <EventRecordID>4002</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:08:31.0000000Z" />
      <EventRecordID>4001</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:03:50.0000000Z" />
      <EventRecordID>4000</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:12:45.0000000Z" />
      <EventRecordID>3999</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:34:56.0000000Z" />
      <EventRecordID>3998</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:36:07.0000000Z" />
      <EventRecordID>3997</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:01:02.0000000Z" />
      <EventRecordID>3996</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:25:06.0000000Z" />
      <EventRecordID>3995</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:17:31.0000000Z" />
      <EventRecordID>3994</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:30:09.0000000Z" />
      <EventRecordID>3993</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:18:30.0000000Z" />
      <EventRecordID>3992</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:43:41.0000000Z" />
      <EventRecordID>3991</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:26:18.0000000Z" />
      <EventRecordID>3990</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:22:26.0000000Z" />
      <EventRecordID>3989</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:41:24.0000000Z" />
      <EventRecordID>3988</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:36:37.0000000Z" />
      <EventRecordID>3987</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:27:03.0000000Z" />
      <EventRecordID>3986</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:10:19.0000000Z" />
      <EventRecordID>3985</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:09:28.0000000Z" />
      <EventRecordID>3984</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:20:05.0000000Z" />
      <EventRecordID>3983</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:03:37.0000000Z" />
      <EventRecordID>3982</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:34:59.0000000Z" />
      <EventRecordID>3981</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:27:12.0000000Z" />
      <EventRecordID>3980</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:37:36.0000000Z" />
      <EventRecordID>3979</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:45:55.0000000Z" />
      <EventRecordID>3978</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:12:10.0000000Z" />
      <EventRecordID>3977</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:19:02.0000000Z" />
      <EventRecordID>3976</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:22:23.0000000Z" />
      <EventRecordID>3975</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:54:34.0000000Z" />
      <EventRecordID>3974</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:42:31.0000000Z" />
      <EventRecordID>3973</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:24:00.0000000Z" />
      <EventRecordID>3972</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:40:01.0000000Z" />
      <EventRecordID>3971</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:36:24.0000000Z" />
      <EventRecordID>3970</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:41:09.0000000Z" />
      <EventRecordID>3969</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:59:22.0000000Z" />
      <EventRecordID>3968</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:15:46.0000000Z" />
      <EventRecordID>3967</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:29:43.0000000Z" />
      <EventRecordID>3966</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:40:05.0000000Z" />
      <EventRecordID>3965</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:17:49.0000000Z" />
      <EventRecordID>3964</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:11:42.0000000Z" />
      <EventRecordID>3963</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:50:25.0000000Z" />
      <EventRecordID>3962</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:04:37.0000000Z" />
      <EventRecordID>3961</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:52:48.0000000Z" />
      <EventRecordID>3960</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:13:04.0000000Z" />
      <EventRecordID>3959</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:44:57.0000000Z" />
      <EventRecordID>3958</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:59:12.0000000Z" />
      <EventRecordID>3957</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:09:31.0000000Z" />
      <EventRecordID>3956</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:26:50.0000000Z" />
      <EventRecordID>3955</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:49:29.0000000Z" />
      <EventRecordID>3954</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:24:15.0000000Z" />
      <EventRecordID>3953</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:03:19.0000000Z" />
      <EventRecordID>3952</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:54:25.0000000Z" />
      <EventRecordID>3951</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:03:28.0000000Z" />
      <EventRecordID>3950</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:30:36.0000000Z" />
      <EventRecordID>3949</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:52:30.0000000Z" />
      <EventRecordID>3948</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:40:41.0000000Z" />
      <EventRecordID>3947</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:46:32.0000000Z" />
      <EventRecordID>3946</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:28:18.0000000Z" />
      <EventRecordID>3945</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:52:39.0000000Z" />
      <EventRecordID>3944</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:48:36.0000000Z" />
      <EventRecordID>3943</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:50:35.0000000Z" />
      <EventRecordID>3942</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:16:39.0000000Z" />
      <EventRecordID>3941</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:33:18.0000000Z" />
      <EventRecordID>3940</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:32:50.0000000Z" />
      <EventRecordID>3939</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:19:05.0000000Z" />
      <EventRecordID>3938</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:18:29.0000000Z" />
      <EventRecordID>3937</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:27:19.0000000Z" />
      <EventRecordID>3936</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:38:50.0000000Z" />
      <EventRecordID>3935</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:21:03.0000000Z" />
      <EventRecordID>3934</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:47:52.0000000Z" />
      <EventRecordID>3933</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:00:04.0000000Z" />
      <EventRecordID>3932</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:55:46.0000000Z" />
      <EventRecordID>3931</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:45:49.0000000Z" />
      <EventRecordID>3930</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:16:01.0000000Z" />
      <EventRecordID>3929</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:01:12.0000000Z" />
      <EventRecordID>3928</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:43:37.0000000Z" />
      <EventRecordID>3927</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:56:45.0000000Z" />
      <EventRecordID>3926</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:45:53.0000000Z" />
      <EventRecordID>3925</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:38:23.0000000Z" />
      <EventRecordID>3924</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:00:51.0000000Z" />
      <EventRecordID>3923</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:32:49.0000000Z" />
      <EventRecordID>3922</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:32:27.0000000Z" />
      <EventRecordID>3921</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:25:03.0000000Z" />
      <EventRecordID>3920</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:39:02.0000000Z" />
      <EventRecordID>3919</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:48:28.0000000Z" />
      <EventRecordID>3918</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:15:51.0000000Z" />
      <EventRecordID>3917</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:30:12.0000000Z" />
      <EventRecordID>3916</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:11:10.0000000Z" />
      <EventRecordID>3915</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:17:01.0000000Z" />
      <EventRecordID>3914</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:02:27.0000000Z" />
      <EventRecordID>3913</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:15:36.0000000Z" />
      <EventRecordID>3912</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:17:01.0000000Z" />
      <EventRecordID>3911</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:42:55.0000000Z" />
      <EventRecordID>3910</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:38:46.0000000Z" />
      <EventRecordID>3909</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:13:51.0000000Z" />
      <EventRecordID>3908</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:39:05.0000000Z" />
      <EventRecordID>3907</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:01:21.0000000Z" />
      <EventRecordID>3906</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:29:16.0000000Z" />
      <EventRecordID>3905</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:32:22.0000000Z" />
      <EventRecordID>3904</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:01:14.0000000Z" />
      <EventRecordID>3903</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:08:33.0000000Z" />
      <EventRecordID>3902</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:13:30.0000000Z" />
      <EventRecordID>3901</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:30:00.0000000Z" />
      <EventRecordID>3900</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:00:57.0000000Z" />
      <EventRecordID>3899</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:09:43.0000000Z" />
      <EventRecordID>3898</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:04:00.0000000Z" />
      <EventRecordID>3897</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:32:47.0000000Z" />
      <EventRecordID>3896</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:39:41.0000000Z" />
      <EventRecordID>3895</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:05:44.0000000Z" />
      <EventRecordID>3894</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:36:38.0000000Z" />
      <EventRecordID>3893</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:10:05.0000000Z" />
      <EventRecordID>3892</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:40:23.0000000Z" />
      <EventRecordID>3891</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:56:49.0000000Z" />
      <EventRecordID>3890</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:06:13.0000000Z" />
      <EventRecordID>3889</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:56:42.0000000Z" />
      <EventRecordID>3888</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:02:39.0000000Z" />
      <EventRecordID>3887</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:28:51.0000000Z" />
      <EventRecordID>3886</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:38:49.0000000Z" />
      <EventRecordID>3885</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:47:09.0000000Z" />
      <EventRecordID>3884</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:03:41.0000000Z" />
      <EventRecordID>3883</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:13:21.0000000Z" />
      <EventRecordID>3882</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:50:09.0000000Z" />
      <EventRecordID>3881</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:02:04.0000000Z" />
      <EventRecordID>3880</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:07:38.0000000Z" />
      <EventRecordID>3879</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:57:09.0000000Z" />
      <EventRecordID>3878</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:30:56.0000000Z" />
      <EventRecordID>3877</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:59:58.0000000Z" />
      <EventRecordID>3876</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:57:02.0000000Z" />
      <EventRecordID>3875</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:30:28.0000000Z" />
      <EventRecordID>3874</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:51:45.0000000Z" />
      <EventRecordID>3873</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:53:00.0000000Z" />
      <EventRecordID>3872</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:00:07.0000000Z" />
      <EventRecordID>3871</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:18:11.0000000Z" />
      <EventRecordID>3870</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:37:38.0000000Z" />
      <EventRecordID>3869</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:42:56.0000000Z" />
      <EventRecordID>3868</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:07:23.0000000Z" />
      <EventRecordID>3867</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:17:12.0000000Z" />
      <EventRecordID>3866</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:38:21.0000000Z" />
      <EventRecordID>3865</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:57:06.0000000Z" />
      <EventRecordID>3864</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:51:08.0000000Z" />
      <EventRecordID>3863</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:39:55.0000000Z" />
      <EventRecordID>3862</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:47:31.0000000Z" />
      <EventRecordID>3861</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:07:45.0000000Z" />
      <EventRecordID>3860</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:50:21.0000000Z" />
      <EventRecordID>3859</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:12:40.0000000Z" />
      <EventRecordID>3858</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:50:12.0000000Z" />
      <EventRecordID>3857</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:05:42.0000000Z" />
      <EventRecordID>3856</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:08:22.0000000Z" />
      <EventRecordID>3855</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:19:25.0000000Z" />
      <EventRecordID>3854</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:42:05.0000000Z" />
      <EventRecordID>3853</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:54:39.0000000Z" />
      <EventRecordID>3852</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:51:08.0000000Z" />
      <EventRecordID>3851</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:21:54.0000000Z" />
      <EventRecordID>3850</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:58:50.0000000Z" />
      <EventRecordID>3849</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:24:44.0000000Z" />
      <EventRecordID>3848</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:19:26.0000000Z" />
      <EventRecordID>3847</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:08:01.0000000Z" />
      <EventRecordID>3846</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:26:06.0000000Z" />
      <EventRecordID>3845</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:59:18.0000000Z" />
      <EventRecordID>3844</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:02:56.0000000Z" />
      <EventRecordID>3843</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:08:04.0000000Z" />
      <EventRecordID>3842</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:10:50.0000000Z" />
      <EventRecordID>3841</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:41:07.0000000Z" />
      <EventRecordID>3840</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:40:58.0000000Z" />
      <EventRecordID>3839</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:30:39.0000000Z" />
      <EventRecordID>3838</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:51:33.0000000Z" />
      <EventRecordID>3837</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:58:00.0000000Z" />
      <EventRecordID>3836</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:36:30.0000000Z" />
      <EventRecordID>3835</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:42:59.0000000Z" />
      <EventRecordID>3834</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:49:44.0000000Z" />
      <EventRecordID>3833</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:51:47.0000000Z" />
      <EventRecordID>3832</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:33:58.0000000Z" />
      <EventRecordID>3831</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:25:31.0000000Z" />
      <EventRecordID>3830</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:24:16.0000000Z" />
      <EventRecordID>3829</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:27:17.0000000Z" />
      <EventRecordID>3828</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:25:11.0000000Z" />
      <EventRecordID>3827</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:33:28.0000000Z" />
      <EventRecordID>3826</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:16:15.0000000Z" />
      <EventRecordID>3825</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:21:25.0000000Z" />
      <EventRecordID>3824</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:40:23.0000000Z" />
      <EventRecordID>3823</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:16:45.0000000Z" />
      <EventRecordID>3822</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:33:29.0000000Z" />
      <EventRecordID>3821</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:19:46.0000000Z" />
      <EventRecordID>3820</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:52:31.0000000Z" />
      <EventRecordID>3819</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:56:25.0000000Z" />
      <EventRecordID>3818</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:22:33.0000000Z" />
      <EventRecordID>3817</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:21:47.0000000Z" />
      <EventRecordID>3816</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:43:27.0000000Z" />
      <EventRecordID>3815</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:25:08.0000000Z" />
      <EventRecordID>3814</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:05:01.0000000Z" />
      <EventRecordID>3813</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:22:58.0000000Z" />
      <EventRecordID>3812</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:07:43.0000000Z" />
      <EventRecordID>3811</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:45:11.0000000Z" />
      <EventRecordID>3810</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:10:57.0000000Z" />
      <EventRecordID>3809</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:46:56.0000000Z" />
      <EventRecordID>3808</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:02:19.0000000Z" />
      <EventRecordID>3807</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:10:28.0000000Z" />
      <EventRecordID>3806</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:19:51.0000000Z" />
      <EventRecordID>3805</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:26:22.0000000Z" />
      <EventRecordID>3804</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:16:10.0000000Z" />
      <EventRecordID>3803</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:01:11.0000000Z" />
      <EventRecordID>3802</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:20:07.0000000Z" />
      <EventRecordID>3801</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:07:09.0000000Z" />
      <EventRecordID>3800</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:17:28.0000000Z" />
      <EventRecordID>3799</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:07:39.0000000Z" />
      <EventRecordID>3798</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:45:56.0000000Z" />
      <EventRecordID>3797</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:33:15.0000000Z" />
      <EventRecordID>3796</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:37:17.0000000Z" />
      <EventRecordID>3795</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:36:46.0000000Z" />
      <EventRecordID>3794</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:36:05.0000000Z" />
      <EventRecordID>3793</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:53:18.0000000Z" />
      <EventRecordID>3792</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:45:54.0000000Z" />
      <EventRecordID>3791</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:04:01.0000000Z" />
      <EventRecordID>3790</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:50:05.0000000Z" />
      <EventRecordID>3789</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:05:47.0000000Z" />
      <EventRecordID>3788</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:47:52.0000000Z" />
      <EventRecordID>3787</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:21:11.0000000Z" />
      <EventRecordID>3786</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:08:57.0000000Z" />
      <EventRecordID>3785</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:33:45.0000000Z" />
      <EventRecordID>3784</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:02:11.0000000Z" />
      <EventRecordID>3783</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:45:39.0000000Z" />
      <EventRecordID>3782</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:53:12.0000000Z" />
      <EventRecordID>3781</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:10:38.0000000Z" />
      <EventRecordID>3780</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:49:03.0000000Z" />
      <EventRecordID>3779</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:16:05.0000000Z" />
      <EventRecordID>3778</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:01:03.0000000Z" />
      <EventRecordID>3777</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:50:41.0000000Z" />
      <EventRecordID>3776</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:21:50.0000000Z" />
      <EventRecordID>3775</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:28:08.0000000Z" />
      <EventRecordID>3774</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:54:23.0000000Z" />
      <EventRecordID>3773</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:35:42.0000000Z" />
      <EventRecordID>3772</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:47:12.0000000Z" />
      <EventRecordID>3771</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:11:48.0000000Z" />
      <EventRecordID>3770</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:18:31.0000000Z" />
      <EventRecordID>3769</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:22:59.0000000Z" />
      <EventRecordID>3768</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:38:12.0000000Z" />
      <EventRecordID>3767</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:18:35.0000000Z" />
      <EventRecordID>3766</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:35:45.0000000Z" />
      <EventRecordID>3765</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:53:25.0000000Z" />
      <EventRecordID>3764</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:38:27.0000000Z" />
      <EventRecordID>3763</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:08:07.0000000Z" />
      <EventRecordID>3762</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:51:04.0000000Z" />
      <EventRecordID>3761</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:40:57.0000000Z" />
      <EventRecordID>3760</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:33:51.0000000Z" />
      <EventRecordID>3759</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:35:19.0000000Z" />
      <EventRecordID>3758</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:40:13.0000000Z" />
      <EventRecordID>3757</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:52:37.0000000Z" />
      <EventRecordID>3756</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:26:02.0000000Z" />
      <EventRecordID>3755</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:30:31.0000000Z" />
      <EventRecordID>3754</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:08:14.0000000Z" />
      <EventRecordID>3753</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:14:07.0000000Z" />
      <EventRecordID>3752</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:14:28.0000000Z" />
      <EventRecordID>3751</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:32:02.0000000Z" />
      <EventRecordID>3750</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:15:56.0000000Z" />
      <EventRecordID>3749</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:46:52.0000000Z" />
      <EventRecordID>3748</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:53:57.0000000Z" />
      <EventRecordID>3747</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:02:41.0000000Z" />
      <EventRecordID>3746</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:03:50.0000000Z" />
      <EventRecordID>3745</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:50:09.0000000Z" />
      <EventRecordID>3744</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:20:36.0000000Z" />
      <EventRecordID>3743</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:32:42.0000000Z" />
      <EventRecordID>3742</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:04:06.0000000Z" />
      <EventRecordID>3741</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:30:23.0000000Z" />
      <EventRecordID>3740</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:11:03.0000000Z" />
      <EventRecordID>3739</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:16:15.0000000Z" />
      <EventRecordID>3738</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:44:20.0000000Z" />
      <EventRecordID>3737</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:17:48.0000000Z" />
      <EventRecordID>3736</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:45:13.0000000Z" />
      <EventRecordID>3735</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:11:49.0000000Z" />
      <EventRecordID>3734</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:59:29.0000000Z" />
      <EventRecordID>3733</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:38:03.0000000Z" />
      <EventRecordID>3732</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:44:28.0000000Z" />
      <EventRecordID>3731</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:21:00.0000000Z" />
      <EventRecordID>3730</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:20:50.0000000Z" />
      <EventRecordID>3729</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:12:23.0000000Z" />
      <EventRecordID>3728</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:13:50.0000000Z" />
      <EventRecordID>3727</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:56:38.0000000Z" />
      <EventRecordID>3726</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:47:22.0000000Z" />
      <EventRecordID>3725</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:08:33.0000000Z" />
      <EventRecordID>3724</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:34:19.0000000Z" />
      <EventRecordID>3723</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:32:20.0000000Z" />
      <EventRecordID>3722</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:23:53.0000000Z" />
      <EventRecordID>3721</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:31:08.0000000Z" />
      <EventRecordID>3720</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:54:52.0000000Z" />
      <EventRecordID>3719</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:26:19.0000000Z" />
      <EventRecordID>3718</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:38:42.0000000Z" />
      <EventRecordID>3717</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:40:00.0000000Z" />
      <EventRecordID>3716</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:31:38.0000000Z" />
      <EventRecordID>3715</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:08:22.0000000Z" />
      <EventRecordID>3714</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:47:49.0000000Z" />
      <EventRecordID>3713</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:03:37.0000000Z" />
      <EventRecordID>3712</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:27:54.0000000Z" />
      <EventRecordID>3711</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:09:27.0000000Z" />
      <EventRecordID>3710</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:21:28.0000000Z" />
      <EventRecordID>3709</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:29:01.0000000Z" />
      <EventRecordID>3708</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:59:02.0000000Z" />
      <EventRecordID>3707</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:23:06.0000000Z" />
      <EventRecordID>3706</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:32:07.0000000Z" />
      <EventRecordID>3705</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:15:31.0000000Z" />
      <EventRecordID>3704</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:04:25.0000000Z" />
      <EventRecordID>3703</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:35:32.0000000Z" />
      <EventRecordID>3702</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:56:49.0000000Z" />
      <EventRecordID>3701</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:19:14.0000000Z" />
      <EventRecordID>3700</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:59:08.0000000Z" />
      <EventRecordID>3699</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:52:08.0000000Z" />
      <EventRecordID>3698</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:06:37.0000000Z" />
      <EventRecordID>3697</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:49:17.0000000Z" />
      <EventRecordID>3696</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:42:30.0000000Z" />
      <EventRecordID>3695</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:08:44.0000000Z" />
      <EventRecordID>3694</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:15:00.0000000Z" />
      <EventRecordID>3693</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:25:51.0000000Z" />
      <EventRecordID>3692</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:58:51.0000000Z" />
      <EventRecordID>3691</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:36:02.0000000Z" />
      <EventRecordID>3690</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:47:44.0000000Z" />
      <EventRecordID>3689</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:41:41.0000000Z" />
      <EventRecordID>3688</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:00:15.0000000Z" />
      <EventRecordID>3687</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:18:35.0000000Z" />
      <EventRecordID>3686</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:31:05.0000000Z" />
      <EventRecordID>3685</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:02:11.0000000Z" />
      <EventRecordID>3684</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:47:36.0000000Z" />
      <EventRecordID>3683</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:01:16.0000000Z" />
      <EventRecordID>3682</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:29:07.0000000Z" />
      <EventRecordID>3681</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:20:21.0000000Z" />
      <EventRecordID>3680</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:08:22.0000000Z" />
      <EventRecordID>3679</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:56:16.0000000Z" />
      <EventRecordID>3678</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:21:38.0000000Z" />
      <EventRecordID>3677</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>noah.davis successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:25:37.0000000Z" />
      <EventRecordID>3676</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:22:39.0000000Z" />
      <EventRecordID>3675</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:39:34.0000000Z" />
      <EventRecordID>3674</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:19:38.0000000Z" />
      <EventRecordID>3673</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:23:36.0000000Z" />
      <EventRecordID>3672</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:56:58.0000000Z" />
      <EventRecordID>3671</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:45:13.0000000Z" />
      <EventRecordID>3670</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:29:00.0000000Z" />
      <EventRecordID>3669</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:33:18.0000000Z" />
      <EventRecordID>3668</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:16:34.0000000Z" />
      <EventRecordID>3667</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:04:20.0000000Z" />
      <EventRecordID>3666</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:14:23.0000000Z" />
      <EventRecordID>3665</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:36:28.0000000Z" />
      <EventRecordID>3664</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:01:47.0000000Z" />
      <EventRecordID>3663</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:21:52.0000000Z" />
      <EventRecordID>3662</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:26:15.0000000Z" />
      <EventRecordID>3661</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:44:32.0000000Z" />
      <EventRecordID>3660</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:07:23.0000000Z" />
      <EventRecordID>3659</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:09:09.0000000Z" />
      <EventRecordID>3658</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:34:44.0000000Z" />
      <EventRecordID>3657</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:08:25.0000000Z" />
      <EventRecordID>3656</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:51:31.0000000Z" />
      <EventRecordID>3655</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:56:53.0000000Z" />
      <EventRecordID>3654</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:15:46.0000000Z" />
      <EventRecordID>3653</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:35:57.0000000Z" />
      <EventRecordID>3652</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:16:29.0000000Z" />
      <EventRecordID>3651</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:52:33.0000000Z" />
      <EventRecordID>3650</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:07:49.0000000Z" />
      <EventRecordID>3649</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:12:36.0000000Z" />
      <EventRecordID>3648</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:41:21.0000000Z" />
      <EventRecordID>3647</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:19:11.0000000Z" />
      <EventRecordID>3646</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:56:14.0000000Z" />
      <EventRecordID>3645</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:52:48.0000000Z" />
      <EventRecordID>3644</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:55:57.0000000Z" />
      <EventRecordID>3643</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:56:13.0000000Z" />
      <EventRecordID>3642</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:49:54.0000000Z" />
      <EventRecordID>3641</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:33:11.0000000Z" />
      <EventRecordID>3640</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:20:34.0000000Z" />
      <EventRecordID>3639</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:46:22.0000000Z" />
      <EventRecordID>3638</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:55:29.0000000Z" />
      <EventRecordID>3637</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:14:34.0000000Z" />
      <EventRecordID>3636</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:47:23.0000000Z" />
      <EventRecordID>3635</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:57:23.0000000Z" />
      <EventRecordID>3634</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:36:58.0000000Z" />
      <EventRecordID>3633</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:35:04.0000000Z" />
      <EventRecordID>3632</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:35:05.0000000Z" />
      <EventRecordID>3631</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:38:26.0000000Z" />
      <EventRecordID>3630</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:20:48.0000000Z" />
      <EventRecordID>3629</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:16:44.0000000Z" />
      <EventRecordID>3628</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:23:07.0000000Z" />
      <EventRecordID>3627</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:03:21.0000000Z" />
      <EventRecordID>3626</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:57:26.0000000Z" />
      <EventRecordID>3625</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:03:08.0000000Z" />
      <EventRecordID>3624</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:56:49.0000000Z" />
      <EventRecordID>3623</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:29:13.0000000Z" />
      <EventRecordID>3622</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:44:41.0000000Z" />
      <EventRecordID>3621</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:00:44.0000000Z" />
      <EventRecordID>3620</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:32:24.0000000Z" />
      <EventRecordID>3619</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:52:43.0000000Z" />
      <EventRecordID>3618</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:39:04.0000000Z" />
      <EventRecordID>3617</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:31:01.0000000Z" />
      <EventRecordID>3616</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:16:12.0000000Z" />
      <EventRecordID>3615</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:38:58.0000000Z" />
      <EventRecordID>3614</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:20:20.0000000Z" />
      <EventRecordID>3613</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:02:09.0000000Z" />
      <EventRecordID>3612</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:10:31.0000000Z" />
      <EventRecordID>3611</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:54:58.0000000Z" />
      <EventRecordID>3610</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:38:10.0000000Z" />
      <EventRecordID>3609</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:38:05.0000000Z" />
      <EventRecordID>3608</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:47:01.0000000Z" />
      <EventRecordID>3607</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:19:13.0000000Z" />
      <EventRecordID>3606</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:38:20.0000000Z" />
      <EventRecordID>3605</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:58:28.0000000Z" />
      <EventRecordID>3604</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:06:50.0000000Z" />
      <EventRecordID>3603</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:58:29.0000000Z" />
      <EventRecordID>3602</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:46:52.0000000Z" />
      <EventRecordID>3601</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:14:22.0000000Z" />
      <EventRecordID>3600</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:33:02.0000000Z" />
      <EventRecordID>3599</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:15:37.0000000Z" />
      <EventRecordID>3598</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:50:58.0000000Z" />
      <EventRecordID>3597</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:13:02.0000000Z" />
      <EventRecordID>3596</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:25:30.0000000Z" />
      <EventRecordID>3595</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:23:14.0000000Z" />
      <EventRecordID>3594</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:08:09.0000000Z" />
      <EventRecordID>3593</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:24:23.0000000Z" />
      <EventRecordID>3592</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:45:32.0000000Z" />
      <EventRecordID>3591</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:33:29.0000000Z" />
      <EventRecordID>3590</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:27:09.0000000Z" />
      <EventRecordID>3589</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:33:49.0000000Z" />
      <EventRecordID>3588</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:25:54.0000000Z" />
      <EventRecordID>3587</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:41:26.0000000Z" />
      <EventRecordID>3586</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:05:53.0000000Z" />
      <EventRecordID>3585</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:56:21.0000000Z" />
      <EventRecordID>3584</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:12:44.0000000Z" />
      <EventRecordID>3583</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:01:41.0000000Z" />
      <EventRecordID>3582</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:20:27.0000000Z" />
      <EventRecordID>3581</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:50:37.0000000Z" />
      <EventRecordID>3580</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:00:24.0000000Z" />
      <EventRecordID>3579</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:18:23.0000000Z" />
      <EventRecordID>3578</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:10:06.0000000Z" />
      <EventRecordID>3577</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:25:29.0000000Z" />
      <EventRecordID>3576</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:46:15.0000000Z" />
      <EventRecordID>3575</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:41:08.0000000Z" />
      <EventRecordID>3574</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:22:44.0000000Z" />
      <EventRecordID>3573</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:34:39.0000000Z" />
      <EventRecordID>3572</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:08:51.0000000Z" />
      <EventRecordID>3571</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:28:50.0000000Z" />
      <EventRecordID>3570</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:26:39.0000000Z" />
      <EventRecordID>3569</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:05:52.0000000Z" />
      <EventRecordID>3568</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:50:41.0000000Z" />
      <EventRecordID>3567</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:49:24.0000000Z" />
      <EventRecordID>3566</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:33:28.0000000Z" />
      <EventRecordID>3565</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:23:22.0000000Z" />
      <EventRecordID>3564</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:06:57.0000000Z" />
      <EventRecordID>3563</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:55:40.0000000Z" />
      <EventRecordID>3562</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:36:16.0000000Z" />
      <EventRecordID>3561</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:12:15.0000000Z" />
      <EventRecordID>3560</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:33:17.0000000Z" />
      <EventRecordID>3559</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:22:25.0000000Z" />
      <EventRecordID>3558</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:56:44.0000000Z" />
      <EventRecordID>3557</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:45:07.0000000Z" />
      <EventRecordID>3556</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:37:05.0000000Z" />
      <EventRecordID>3555</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:54:09.0000000Z" />
      <EventRecordID>3554</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:15:08.0000000Z" />
      <EventRecordID>3553</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:57:54.0000000Z" />
      <EventRecordID>3552</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:18:24.0000000Z" />
      <EventRecordID>3551</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:32:08.0000000Z" />
      <EventRecordID>3550</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:21:30.0000000Z" />
      <EventRecordID>3549</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:03:48.0000000Z" />
      <EventRecordID>3548</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:28:34.0000000Z" />
      <EventRecordID>3547</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:16:38.0000000Z" />
      <EventRecordID>3546</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:37:57.0000000Z" />
      <EventRecordID>3545</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:08:41.0000000Z" />
      <EventRecordID>3544</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:05:18.0000000Z" />
      <EventRecordID>3543</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:01:13.0000000Z" />
      <EventRecordID>3542</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:22:24.0000000Z" />
      <EventRecordID>3541</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:14:52.0000000Z" />
      <EventRecordID>3540</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:36:14.0000000Z" />
      <EventRecordID>3539</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:19:06.0000000Z" />
      <EventRecordID>3538</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:11:59.0000000Z" />
      <EventRecordID>3537</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:06:43.0000000Z" />
      <EventRecordID>3536</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:09:43.0000000Z" />
      <EventRecordID>3535</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:18:08.0000000Z" />
      <EventRecordID>3534</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:34:32.0000000Z" />
      <EventRecordID>3533</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:39:01.0000000Z" />
      <EventRecordID>3532</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:18:06.0000000Z" />
      <EventRecordID>3531</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:56:32.0000000Z" />
      <EventRecordID>3530</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:37:18.0000000Z" />
      <EventRecordID>3529</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:40:24.0000000Z" />
      <EventRecordID>3528</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:31:02.0000000Z" />
      <EventRecordID>3527</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:51:57.0000000Z" />
      <EventRecordID>3526</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:46:38.0000000Z" />
      <EventRecordID>3525</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:07:48.0000000Z" />
      <EventRecordID>3524</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:33:39.0000000Z" />
      <EventRecordID>3523</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:25:16.0000000Z" />
      <EventRecordID>3522</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:47:00.0000000Z" />
      <EventRecordID>3521</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:53:50.0000000Z" />
      <EventRecordID>3520</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:57:17.0000000Z" />
      <EventRecordID>3519</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:34:51.0000000Z" />
      <EventRecordID>3518</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:55:55.0000000Z" />
      <EventRecordID>3517</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:10:09.0000000Z" />
      <EventRecordID>3516</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:29:28.0000000Z" />
      <EventRecordID>3515</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:40:05.0000000Z" />
      <EventRecordID>3514</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:55:13.0000000Z" />
      <EventRecordID>3513</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:00:11.0000000Z" />
      <EventRecordID>3512</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:21:25.0000000Z" />
      <EventRecordID>3511</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:06:19.0000000Z" />
      <EventRecordID>3510</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:57:25.0000000Z" />
      <EventRecordID>3509</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:54:22.0000000Z" />
      <EventRecordID>3508</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:34:10.0000000Z" />
      <EventRecordID>3507</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:52:02.0000000Z" />
      <EventRecordID>3506</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:15:44.0000000Z" />
      <EventRecordID>3505</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:59:03.0000000Z" />
      <EventRecordID>3504</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:14:41.0000000Z" />
      <EventRecordID>3503</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:20:53.0000000Z" />
      <EventRecordID>3502</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:37:36.0000000Z" />
      <EventRecordID>3501</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:25:29.0000000Z" />
      <EventRecordID>3500</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:14:47.0000000Z" />
      <EventRecordID>3499</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:41:12.0000000Z" />
      <EventRecordID>3498</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:14:29.0000000Z" />
      <EventRecordID>3497</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:37:12.0000000Z" />
      <EventRecordID>3496</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:57:02.0000000Z" />
      <EventRecordID>3495</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:22:07.0000000Z" />
      <EventRecordID>3494</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:33:54.0000000Z" />
      <EventRecordID>3493</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:01:14.0000000Z" />
      <EventRecordID>3492</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:07:51.0000000Z" />
      <EventRecordID>3491</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:32:28.0000000Z" />
      <EventRecordID>3490</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:21:41.0000000Z" />
      <EventRecordID>3489</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:03:15.0000000Z" />
      <EventRecordID>3488</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:27:13.0000000Z" />
      <EventRecordID>3487</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:33:09.0000000Z" />
      <EventRecordID>3486</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:51:51.0000000Z" />
      <EventRecordID>3485</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:45:53.0000000Z" />
      <EventRecordID>3484</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:16:50.0000000Z" />
      <EventRecordID>3483</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:05:29.0000000Z" />
      <EventRecordID>3482</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:33:22.0000000Z" />
      <EventRecordID>3481</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:40:55.0000000Z" />
      <EventRecordID>3480</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:10:15.0000000Z" />
      <EventRecordID>3479</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:34:28.0000000Z" />
      <EventRecordID>3478</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:17:41.0000000Z" />
      <EventRecordID>3477</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:38:35.0000000Z" />
      <EventRecordID>3476</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:34:16.0000000Z" />
      <EventRecordID>3475</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:02:32.0000000Z" />
      <EventRecordID>3474</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:41:57.0000000Z" />
      <EventRecordID>3473</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:03:53.0000000Z" />
      <EventRecordID>3472</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:22:55.0000000Z" />
      <EventRecordID>3471</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:28:20.0000000Z" />
      <EventRecordID>3470</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:39:43.0000000Z" />
      <EventRecordID>3469</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:38:36.0000000Z" />
      <EventRecordID>3468</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:46:04.0000000Z" />
      <EventRecordID>3467</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:05:11.0000000Z" />
      <EventRecordID>3466</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:20:52.0000000Z" />
      <EventRecordID>3465</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:06:56.0000000Z" />
      <EventRecordID>3464</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:13:13.0000000Z" />
      <EventRecordID>3463</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:41:01.0000000Z" />
      <EventRecordID>3462</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:44:01.0000000Z" />
      <EventRecordID>3461</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:15:58.0000000Z" />
      <EventRecordID>3460</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:54:27.0000000Z" />
      <EventRecordID>3459</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:08:39.0000000Z" />
      <EventRecordID>3458</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:33:50.0000000Z" />
      <EventRecordID>3457</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:30:19.0000000Z" />
      <EventRecordID>3456</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:17:46.0000000Z" />
      <EventRecordID>3455</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:01:45.0000000Z" />
      <EventRecordID>3454</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:24:35.0000000Z" />
      <EventRecordID>3453</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:17:13.0000000Z" />
      <EventRecordID>3452</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:55:20.0000000Z" />
      <EventRecordID>3451</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:17:02.0000000Z" />
      <EventRecordID>3450</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:19:57.0000000Z" />
      <EventRecordID>3449</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:52:23.0000000Z" />
      <EventRecordID>3448</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:28:54.0000000Z" />
      <EventRecordID>3447</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:51:31.0000000Z" />
      <EventRecordID>3446</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:31:33.0000000Z" />
      <EventRecordID>3445</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:09:59.0000000Z" />
      <EventRecordID>3444</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:27:13.0000000Z" />
      <EventRecordID>3443</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:31:40.0000000Z" />
      <EventRecordID>3442</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:19:21.0000000Z" />
      <EventRecordID>3441</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:23:19.0000000Z" />
      <EventRecordID>3440</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:48:12.0000000Z" />
      <EventRecordID>3439</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:44:14.0000000Z" />
      <EventRecordID>3438</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:16:39.0000000Z" />
      <EventRecordID>3437</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:53:50.0000000Z" />
      <EventRecordID>3436</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:06:21.0000000Z" />
      <EventRecordID>3435</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:54:52.0000000Z" />
      <EventRecordID>3434</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:25:00.0000000Z" />
      <EventRecordID>3433</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:50:06.0000000Z" />
      <EventRecordID>3432</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:37:26.0000000Z" />
      <EventRecordID>3431</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:36:44.0000000Z" />
      <EventRecordID>3430</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:27:58.0000000Z" />
      <EventRecordID>3429</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:06:16.0000000Z" />
      <EventRecordID>3428</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:05:42.0000000Z" />
      <EventRecordID>3427</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:41:10.0000000Z" />
      <EventRecordID>3426</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:57:15.0000000Z" />
      <EventRecordID>3425</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:14:06.0000000Z" />
      <EventRecordID>3424</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:20:19.0000000Z" />
      <EventRecordID>3423</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:46:37.0000000Z" />
      <EventRecordID>3422</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:51:48.0000000Z" />
      <EventRecordID>3421</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:35:04.0000000Z" />
      <EventRecordID>3420</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:02:55.0000000Z" />
      <EventRecordID>3419</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:51:28.0000000Z" />
      <EventRecordID>3418</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:38:26.0000000Z" />
      <EventRecordID>3417</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:36:25.0000000Z" />
      <EventRecordID>3416</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:39:36.0000000Z" />
      <EventRecordID>3415</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:42:54.0000000Z" />
      <EventRecordID>3414</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:56:26.0000000Z" />
      <EventRecordID>3413</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:59:37.0000000Z" />
      <EventRecordID>3412</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:06:43.0000000Z" />
      <EventRecordID>3411</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:02:38.0000000Z" />
      <EventRecordID>3410</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:52:05.0000000Z" />
      <EventRecordID>3409</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:05:39.0000000Z" />
      <EventRecordID>3408</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:01:16.0000000Z" />
      <EventRecordID>3407</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:34:36.0000000Z" />
      <EventRecordID>3406</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:57:04.0000000Z" />
      <EventRecordID>3405</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:46:08.0000000Z" />
      <EventRecordID>3404</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:23:19.0000000Z" />
      <EventRecordID>3403</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:04:11.0000000Z" />
      <EventRecordID>3402</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:59:21.0000000Z" />
      <EventRecordID>3401</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:18:37.0000000Z" />
      <EventRecordID>3400</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:02:47.0000000Z" />
      <EventRecordID>3399</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:49:16.0000000Z" />
      <EventRecordID>3398</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:22:55.0000000Z" />
      <EventRecordID>3397</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:25:19.0000000Z" />
      <EventRecordID>3396</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:54:24.0000000Z" />
      <EventRecordID>3395</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:09:49.0000000Z" />
      <EventRecordID>3394</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:58:14.0000000Z" />
      <EventRecordID>3393</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:13:03.0000000Z" />
      <EventRecordID>3392</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:54:04.0000000Z" />
      <EventRecordID>3391</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:24:26.0000000Z" />
      <EventRecordID>3390</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:00:02.0000000Z" />
      <EventRecordID>3389</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:37:28.0000000Z" />
      <EventRecordID>3388</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:23:40.0000000Z" />
      <EventRecordID>3387</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:38:37.0000000Z" />
      <EventRecordID>3386</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:45:23.0000000Z" />
      <EventRecordID>3385</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:36:03.0000000Z" />
      <EventRecordID>3384</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:04:21.0000000Z" />
      <EventRecordID>3383</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:46:16.0000000Z" />
      <EventRecordID>3382</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:08:34.0000000Z" />
      <EventRecordID>3381</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:44:36.0000000Z" />
      <EventRecordID>3380</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:07:58.0000000Z" />
      <EventRecordID>3379</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:56:30.0000000Z" />
      <EventRecordID>3378</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:49:38.0000000Z" />
      <EventRecordID>3377</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:48:40.0000000Z" />
      <EventRecordID>3376</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:33:34.0000000Z" />
      <EventRecordID>3375</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:10:28.0000000Z" />
      <EventRecordID>3374</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:33:54.0000000Z" />
      <EventRecordID>3373</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:52:08.0000000Z" />
      <EventRecordID>3372</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:16:00.0000000Z" />
      <EventRecordID>3371</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:05:45.0000000Z" />
      <EventRecordID>3370</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:37:51.0000000Z" />
      <EventRecordID>3369</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:19:44.0000000Z" />
      <EventRecordID>3368</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:28:08.0000000Z" />
      <EventRecordID>3367</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:34:22.0000000Z" />
      <EventRecordID>3366</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:47:00.0000000Z" />
      <EventRecordID>3365</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:37:40.0000000Z" />
      <EventRecordID>3364</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:00:08.0000000Z" />
      <EventRecordID>3363</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:13:21.0000000Z" />
      <EventRecordID>3362</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:56:33.0000000Z" />
      <EventRecordID>3361</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:55:52.0000000Z" />
      <EventRecordID>3360</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:52:41.0000000Z" />
      <EventRecordID>3359</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:00:12.0000000Z" />
      <EventRecordID>3358</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:29:04.0000000Z" />
      <EventRecordID>3357</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:50:20.0000000Z" />
      <EventRecordID>3356</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:53:53.0000000Z" />
      <EventRecordID>3355</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:02:04.0000000Z" />
      <EventRecordID>3354</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:11:59.0000000Z" />
      <EventRecordID>3353</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:05:49.0000000Z" />
      <EventRecordID>3352</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:17:25.0000000Z" />
      <EventRecordID>3351</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:48:52.0000000Z" />
      <EventRecordID>3350</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:40:30.0000000Z" />
      <EventRecordID>3349</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:29:03.0000000Z" />
      <EventRecordID>3348</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:11:35.0000000Z" />
      <EventRecordID>3347</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:42:31.0000000Z" />
      <EventRecordID>3346</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:45:19.0000000Z" />
      <EventRecordID>3345</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:21:52.0000000Z" />
      <EventRecordID>3344</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:31:31.0000000Z" />
      <EventRecordID>3343</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:13:29.0000000Z" />
      <EventRecordID>3342</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:32:49.0000000Z" />
      <EventRecordID>3341</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:44:22.0000000Z" />
      <EventRecordID>3340</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:57:53.0000000Z" />
      <EventRecordID>3339</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:58:53.0000000Z" />
      <EventRecordID>3338</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:10:47.0000000Z" />
      <EventRecordID>3337</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:08:25.0000000Z" />
      <EventRecordID>3336</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:18:50.0000000Z" />
      <EventRecordID>3335</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:51:23.0000000Z" />
      <EventRecordID>3334</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:15:17.0000000Z" />
      <EventRecordID>3333</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:18:17.0000000Z" />
      <EventRecordID>3332</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:53:00.0000000Z" />
      <EventRecordID>3331</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:01:39.0000000Z" />
      <EventRecordID>3330</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:48:12.0000000Z" />
      <EventRecordID>3329</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:45:49.0000000Z" />
      <EventRecordID>3328</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:28:32.0000000Z" />
      <EventRecordID>3327</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:03:49.0000000Z" />
      <EventRecordID>3326</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:21:35.0000000Z" />
      <EventRecordID>3325</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:56:46.0000000Z" />
      <EventRecordID>3324</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:38:10.0000000Z" />
      <EventRecordID>3323</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:58:09.0000000Z" />
      <EventRecordID>3322</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:45:57.0000000Z" />
      <EventRecordID>3321</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:25:43.0000000Z" />
      <EventRecordID>3320</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:09:30.0000000Z" />
      <EventRecordID>3319</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:55:17.0000000Z" />
      <EventRecordID>3318</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:21:30.0000000Z" />
      <EventRecordID>3317</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:09:03.0000000Z" />
      <EventRecordID>3316</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:45:27.0000000Z" />
      <EventRecordID>3315</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:52:34.0000000Z" />
      <EventRecordID>3314</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:33:41.0000000Z" />
      <EventRecordID>3313</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:21:11.0000000Z" />
      <EventRecordID>3312</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:01:34.0000000Z" />
      <EventRecordID>3311</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:33:40.0000000Z" />
      <EventRecordID>3310</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:07:06.0000000Z" />
      <EventRecordID>3309</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:33:06.0000000Z" />
      <EventRecordID>3308</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:55:39.0000000Z" />
      <EventRecordID>3307</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:22:20.0000000Z" />
      <EventRecordID>3306</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:43:11.0000000Z" />
      <EventRecordID>3305</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:27:52.0000000Z" />
      <EventRecordID>3304</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:45:37.0000000Z" />
      <EventRecordID>3303</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:42:52.0000000Z" />
      <EventRecordID>3302</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:25:19.0000000Z" />
      <EventRecordID>3301</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:03:39.0000000Z" />
      <EventRecordID>3300</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:35:26.0000000Z" />
      <EventRecordID>3299</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:53:40.0000000Z" />
      <EventRecordID>3298</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:39:57.0000000Z" />
      <EventRecordID>3297</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:31:24.0000000Z" />
      <EventRecordID>3296</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:21:49.0000000Z" />
      <EventRecordID>3295</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:42:37.0000000Z" />
      <EventRecordID>3294</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:16:39.0000000Z" />
      <EventRecordID>3293</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:09:52.0000000Z" />
      <EventRecordID>3292</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:22:02.0000000Z" />
      <EventRecordID>3291</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:45:56.0000000Z" />
      <EventRecordID>3290</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:03:01.0000000Z" />
      <EventRecordID>3289</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:59:14.0000000Z" />
      <EventRecordID>3288</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:10:22.0000000Z" />
      <EventRecordID>3287</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:56:35.0000000Z" />
      <EventRecordID>3286</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:20:28.0000000Z" />
      <EventRecordID>3285</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:00:24.0000000Z" />
      <EventRecordID>3284</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:57:50.0000000Z" />
      <EventRecordID>3283</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:20:07.0000000Z" />
      <EventRecordID>3282</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:27:56.0000000Z" />
      <EventRecordID>3281</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:20:26.0000000Z" />
      <EventRecordID>3280</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:59:08.0000000Z" />
      <EventRecordID>3279</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:20:59.0000000Z" />
      <EventRecordID>3278</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:51:34.0000000Z" />
      <EventRecordID>3277</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.bryan logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:19:58.0000000Z" />
      <EventRecordID>3276</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:01:12.0000000Z" />
      <EventRecordID>3275</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:41:47.0000000Z" />
      <EventRecordID>3274</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:46:52.0000000Z" />
      <EventRecordID>3273</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:29:32.0000000Z" />
      <EventRecordID>3272</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:59:44.0000000Z" />
      <EventRecordID>3271</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:14:42.0000000Z" />
      <EventRecordID>3270</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:36:28.0000000Z" />
      <EventRecordID>3269</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:06:45.0000000Z" />
      <EventRecordID>3268</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:05:46.0000000Z" />
      <EventRecordID>3267</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:25:27.0000000Z" />
      <EventRecordID>3266</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:52:27.0000000Z" />
      <EventRecordID>3265</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:26:12.0000000Z" />
      <EventRecordID>3264</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:51:11.0000000Z" />
      <EventRecordID>3263</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:21:47.0000000Z" />
      <EventRecordID>3262</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:21:59.0000000Z" />
      <EventRecordID>3261</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:59:27.0000000Z" />
      <EventRecordID>3260</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:22:22.0000000Z" />
      <EventRecordID>3259</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:38:17.0000000Z" />
      <EventRecordID>3258</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:39:28.0000000Z" />
      <EventRecordID>3257</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:59:51.0000000Z" />
      <EventRecordID>3256</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:48:48.0000000Z" />
      <EventRecordID>3255</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:17:07.0000000Z" />
      <EventRecordID>3254</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:21:37.0000000Z" />
      <EventRecordID>3253</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:12:27.0000000Z" />
      <EventRecordID>3252</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:21:17.0000000Z" />
      <EventRecordID>3251</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:30:10.0000000Z" />
      <EventRecordID>3250</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:40:02.0000000Z" />
      <EventRecordID>3249</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:58:45.0000000Z" />
      <EventRecordID>3248</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:32:42.0000000Z" />
      <EventRecordID>3247</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:34:45.0000000Z" />
      <EventRecordID>3246</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:17:32.0000000Z" />
      <EventRecordID>3245</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:16:14.0000000Z" />
      <EventRecordID>3244</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:53:00.0000000Z" />
      <EventRecordID>3243</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:12:56.0000000Z" />
      <EventRecordID>3242</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:05:51.0000000Z" />
      <EventRecordID>3241</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:10:35.0000000Z" />
      <EventRecordID>3240</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:00:46.0000000Z" />
      <EventRecordID>3239</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:01:38.0000000Z" />
      <EventRecordID>3238</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:15:21.0000000Z" />
      <EventRecordID>3237</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:40:57.0000000Z" />
      <EventRecordID>3236</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:40:36.0000000Z" />
      <EventRecordID>3235</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:14:09.0000000Z" />
      <EventRecordID>3234</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:12:03.0000000Z" />
      <EventRecordID>3233</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:30:43.0000000Z" />
      <EventRecordID>3232</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:43:06.0000000Z" />
      <EventRecordID>3231</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:54:37.0000000Z" />
      <EventRecordID>3230</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:34:02.0000000Z" />
      <EventRecordID>3229</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:46:17.0000000Z" />
      <EventRecordID>3228</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:40:30.0000000Z" />
      <EventRecordID>3227</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:07:57.0000000Z" />
      <EventRecordID>3226</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:00:34.0000000Z" />
      <EventRecordID>3225</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:07:50.0000000Z" />
      <EventRecordID>3224</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:32:03.0000000Z" />
      <EventRecordID>3223</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:32:20.0000000Z" />
      <EventRecordID>3222</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:39:36.0000000Z" />
      <EventRecordID>3221</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:55:38.0000000Z" />
      <EventRecordID>3220</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:17:16.0000000Z" />
      <EventRecordID>3219</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:25:34.0000000Z" />
      <EventRecordID>3218</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:40:23.0000000Z" />
      <EventRecordID>3217</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:11:32.0000000Z" />
      <EventRecordID>3216</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:16:31.0000000Z" />
      <EventRecordID>3215</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:37:13.0000000Z" />
      <EventRecordID>3214</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:00:42.0000000Z" />
      <EventRecordID>3213</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:19:27.0000000Z" />
      <EventRecordID>3212</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:15:07.0000000Z" />
      <EventRecordID>3211</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:11:06.0000000Z" />
      <EventRecordID>3210</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:32:34.0000000Z" />
      <EventRecordID>3209</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:54:20.0000000Z" />
      <EventRecordID>3208</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:32:21.0000000Z" />
      <EventRecordID>3207</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:46:18.0000000Z" />
      <EventRecordID>3206</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:51:03.0000000Z" />
      <EventRecordID>3205</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:11:27.0000000Z" />
      <EventRecordID>3204</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:07:37.0000000Z" />
      <EventRecordID>3203</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:15:31.0000000Z" />
      <EventRecordID>3202</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:36:31.0000000Z" />
      <EventRecordID>3201</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:55:05.0000000Z" />
      <EventRecordID>3200</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:41:18.0000000Z" />
      <EventRecordID>3199</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:43:53.0000000Z" />
      <EventRecordID>3198</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:49:33.0000000Z" />
      <EventRecordID>3197</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:07:52.0000000Z" />
      <EventRecordID>3196</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:55:59.0000000Z" />
      <EventRecordID>3195</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:23:19.0000000Z" />
      <EventRecordID>3194</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:16:43.0000000Z" />
      <EventRecordID>3193</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:03:12.0000000Z" />
      <EventRecordID>3192</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:14:36.0000000Z" />
      <EventRecordID>3191</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:37:26.0000000Z" />
      <EventRecordID>3190</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:09:47.0000000Z" />
      <EventRecordID>3189</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:33:33.0000000Z" />
      <EventRecordID>3188</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:30:55.0000000Z" />
      <EventRecordID>3187</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:41:18.0000000Z" />
      <EventRecordID>3186</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:29:11.0000000Z" />
      <EventRecordID>3185</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:58:44.0000000Z" />
      <EventRecordID>3184</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:22:17.0000000Z" />
      <EventRecordID>3183</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:46:49.0000000Z" />
      <EventRecordID>3182</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:04:34.0000000Z" />
      <EventRecordID>3181</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:34:54.0000000Z" />
      <EventRecordID>3180</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:33:56.0000000Z" />
      <EventRecordID>3179</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:01:49.0000000Z" />
      <EventRecordID>3178</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:03:06.0000000Z" />
      <EventRecordID>3177</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:08:28.0000000Z" />
      <EventRecordID>3176</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:38:44.0000000Z" />
      <EventRecordID>3175</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:57:38.0000000Z" />
      <EventRecordID>3174</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:54:38.0000000Z" />
      <EventRecordID>3173</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:44:41.0000000Z" />
      <EventRecordID>3172</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:31:29.0000000Z" />
      <EventRecordID>3171</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:21:05.0000000Z" />
      <EventRecordID>3170</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:48:05.0000000Z" />
      <EventRecordID>3169</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:08:07.0000000Z" />
      <EventRecordID>3168</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:20:13.0000000Z" />
      <EventRecordID>3167</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:31:59.0000000Z" />
      <EventRecordID>3166</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:31:33.0000000Z" />
      <EventRecordID>3165</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:01:14.0000000Z" />
      <EventRecordID>3164</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:02:46.0000000Z" />
      <EventRecordID>3163</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:16:06.0000000Z" />
      <EventRecordID>3162</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:44:08.0000000Z" />
      <EventRecordID>3161</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:46:19.0000000Z" />
      <EventRecordID>3160</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:50:51.0000000Z" />
      <EventRecordID>3159</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:34:05.0000000Z" />
      <EventRecordID>3158</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:40:00.0000000Z" />
      <EventRecordID>3157</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:31:35.0000000Z" />
      <EventRecordID>3156</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:47:57.0000000Z" />
      <EventRecordID>3155</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:04:58.0000000Z" />
      <EventRecordID>3154</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:40:18.0000000Z" />
      <EventRecordID>3153</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:31:03.0000000Z" />
      <EventRecordID>3152</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:11:15.0000000Z" />
      <EventRecordID>3151</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:42:24.0000000Z" />
      <EventRecordID>3150</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:50:24.0000000Z" />
      <EventRecordID>3149</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:57:15.0000000Z" />
      <EventRecordID>3148</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:02:38.0000000Z" />
      <EventRecordID>3147</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:19:59.0000000Z" />
      <EventRecordID>3146</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:23:04.0000000Z" />
      <EventRecordID>3145</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:42:07.0000000Z" />
      <EventRecordID>3144</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:39:31.0000000Z" />
      <EventRecordID>3143</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:27:53.0000000Z" />
      <EventRecordID>3142</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:09:21.0000000Z" />
      <EventRecordID>3141</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:02:03.0000000Z" />
      <EventRecordID>3140</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:35:55.0000000Z" />
      <EventRecordID>3139</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:30:26.0000000Z" />
      <EventRecordID>3138</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:51:44.0000000Z" />
      <EventRecordID>3137</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:53:12.0000000Z" />
      <EventRecordID>3136</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:50:12.0000000Z" />
      <EventRecordID>3135</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:48:27.0000000Z" />
      <EventRecordID>3134</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:37:23.0000000Z" />
      <EventRecordID>3133</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:19:11.0000000Z" />
      <EventRecordID>3132</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:35:31.0000000Z" />
      <EventRecordID>3131</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:15:57.0000000Z" />
      <EventRecordID>3130</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:51:39.0000000Z" />
      <EventRecordID>3129</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:16:53.0000000Z" />
      <EventRecordID>3128</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:16:24.0000000Z" />
      <EventRecordID>3127</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:35:50.0000000Z" />
      <EventRecordID>3126</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:37:25.0000000Z" />
      <EventRecordID>3125</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:15:33.0000000Z" />
      <EventRecordID>3124</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:16:18.0000000Z" />
      <EventRecordID>3123</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:13:43.0000000Z" />
      <EventRecordID>3122</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:17:32.0000000Z" />
      <EventRecordID>3121</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:15:34.0000000Z" />
      <EventRecordID>3120</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:03:06.0000000Z" />
      <EventRecordID>3119</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:06:51.0000000Z" />
      <EventRecordID>3118</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:06:26.0000000Z" />
      <EventRecordID>3117</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:48:06.0000000Z" />
      <EventRecordID>3116</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:56:14.0000000Z" />
      <EventRecordID>3115</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:55:35.0000000Z" />
      <EventRecordID>3114</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:00:03.0000000Z" />
      <EventRecordID>3113</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:51:36.0000000Z" />
      <EventRecordID>3112</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:17:17.0000000Z" />
      <EventRecordID>3111</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:32:18.0000000Z" />
      <EventRecordID>3110</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:46:10.0000000Z" />
      <EventRecordID>3109</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:18:30.0000000Z" />
      <EventRecordID>3108</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:38:03.0000000Z" />
      <EventRecordID>3107</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:25:06.0000000Z" />
      <EventRecordID>3106</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:33:24.0000000Z" />
      <EventRecordID>3105</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:53:14.0000000Z" />
      <EventRecordID>3104</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:53:03.0000000Z" />
      <EventRecordID>3103</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:47:04.0000000Z" />
      <EventRecordID>3102</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:32:28.0000000Z" />
      <EventRecordID>3101</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:51:40.0000000Z" />
      <EventRecordID>3100</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:20:45.0000000Z" />
      <EventRecordID>3099</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:10:55.0000000Z" />
      <EventRecordID>3098</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:56:07.0000000Z" />
      <EventRecordID>3097</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:34:16.0000000Z" />
      <EventRecordID>3096</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:30:27.0000000Z" />
      <EventRecordID>3095</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:08:00.0000000Z" />
      <EventRecordID>3094</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:45:55.0000000Z" />
      <EventRecordID>3093</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:02:19.0000000Z" />
      <EventRecordID>3092</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:56:08.0000000Z" />
      <EventRecordID>3091</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:34:19.0000000Z" />
      <EventRecordID>3090</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:44:29.0000000Z" />
      <EventRecordID>3089</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:24:29.0000000Z" />
      <EventRecordID>3088</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:39:02.0000000Z" />
      <EventRecordID>3087</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:12:28.0000000Z" />
      <EventRecordID>3086</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:23:35.0000000Z" />
      <EventRecordID>3085</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:23:51.0000000Z" />
      <EventRecordID>3084</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:01:27.0000000Z" />
      <EventRecordID>3083</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:55:22.0000000Z" />
      <EventRecordID>3082</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:55:06.0000000Z" />
      <EventRecordID>3081</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:43:50.0000000Z" />
      <EventRecordID>3080</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:52:01.0000000Z" />
      <EventRecordID>3079</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:20:14.0000000Z" />
      <EventRecordID>3078</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:13:11.0000000Z" />
      <EventRecordID>3077</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:03:50.0000000Z" />
      <EventRecordID>3076</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:28:52.0000000Z" />
      <EventRecordID>3075</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:50:00.0000000Z" />
      <EventRecordID>3074</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:53:25.0000000Z" />
      <EventRecordID>3073</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:44:43.0000000Z" />
      <EventRecordID>3072</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:33:52.0000000Z" />
      <EventRecordID>3071</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:34:02.0000000Z" />
      <EventRecordID>3070</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:02:47.0000000Z" />
      <EventRecordID>3069</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:23:33.0000000Z" />
      <EventRecordID>3068</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:05:38.0000000Z" />
      <EventRecordID>3067</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:36:40.0000000Z" />
      <EventRecordID>3066</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:05:46.0000000Z" />
      <EventRecordID>3065</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:26:06.0000000Z" />
      <EventRecordID>3064</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:16:27.0000000Z" />
      <EventRecordID>3063</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:38:52.0000000Z" />
      <EventRecordID>3062</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:47:06.0000000Z" />
      <EventRecordID>3061</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:39:55.0000000Z" />
      <EventRecordID>3060</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:35:52.0000000Z" />
      <EventRecordID>3059</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:32:14.0000000Z" />
      <EventRecordID>3058</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:24:44.0000000Z" />
      <EventRecordID>3057</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:44:02.0000000Z" />
      <EventRecordID>3056</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:34:09.0000000Z" />
      <EventRecordID>3055</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:48:36.0000000Z" />
      <EventRecordID>3054</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:50:04.0000000Z" />
      <EventRecordID>3053</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:39:41.0000000Z" />
      <EventRecordID>3052</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:54:05.0000000Z" />
      <EventRecordID>3051</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:50:41.0000000Z" />
      <EventRecordID>3050</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:23:11.0000000Z" />
      <EventRecordID>3049</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:19:58.0000000Z" />
      <EventRecordID>3048</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:39:48.0000000Z" />
      <EventRecordID>3047</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:24:18.0000000Z" />
      <EventRecordID>3046</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:58:37.0000000Z" />
      <EventRecordID>3045</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:18:33.0000000Z" />
      <EventRecordID>3044</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:51:26.0000000Z" />
      <EventRecordID>3043</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:18:49.0000000Z" />
      <EventRecordID>3042</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:03:50.0000000Z" />
      <EventRecordID>3041</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:57:30.0000000Z" />
      <EventRecordID>3040</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:00:24.0000000Z" />
      <EventRecordID>3039</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:04:17.0000000Z" />
      <EventRecordID>3038</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:46:35.0000000Z" />
      <EventRecordID>3037</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:21:48.0000000Z" />
      <EventRecordID>3036</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:00:52.0000000Z" />
      <EventRecordID>3035</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:00:13.0000000Z" />
      <EventRecordID>3034</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:06:31.0000000Z" />
      <EventRecordID>3033</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:58:45.0000000Z" />
      <EventRecordID>3032</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:09:42.0000000Z" />
      <EventRecordID>3031</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:14:08.0000000Z" />
      <EventRecordID>3030</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:54:58.0000000Z" />
      <EventRecordID>3029</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:49:17.0000000Z" />
      <EventRecordID>3028</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:27:31.0000000Z" />
      <EventRecordID>3027</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:41:52.0000000Z" />
      <EventRecordID>3026</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:25:38.0000000Z" />
      <EventRecordID>3025</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:00:36.0000000Z" />
      <EventRecordID>3024</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:14:17.0000000Z" />
      <EventRecordID>3023</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:19:07.0000000Z" />
      <EventRecordID>3022</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:38:12.0000000Z" />
      <EventRecordID>3021</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:04:55.0000000Z" />
      <EventRecordID>3020</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:49:09.0000000Z" />
      <EventRecordID>3019</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:44:33.0000000Z" />
      <EventRecordID>3018</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:43:39.0000000Z" />
      <EventRecordID>3017</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:06:15.0000000Z" />
      <EventRecordID>3016</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:01:37.0000000Z" />
      <EventRecordID>3015</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:39:36.0000000Z" />
      <EventRecordID>3014</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:52:52.0000000Z" />
      <EventRecordID>3013</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:24:51.0000000Z" />
      <EventRecordID>3012</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:54:05.0000000Z" />
      <EventRecordID>3011</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:57:39.0000000Z" />
      <EventRecordID>3010</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:56:52.0000000Z" />
      <EventRecordID>3009</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:07:39.0000000Z" />
      <EventRecordID>3008</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:27:44.0000000Z" />
      <EventRecordID>3007</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:21:03.0000000Z" />
      <EventRecordID>3006</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:14:37.0000000Z" />
      <EventRecordID>3005</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:49:55.0000000Z" />
      <EventRecordID>3004</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:33:15.0000000Z" />
      <EventRecordID>3003</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:06:00.0000000Z" />
      <EventRecordID>3002</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:14:23.0000000Z" />
      <EventRecordID>3001</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:27:28.0000000Z" />
      <EventRecordID>3000</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:15:40.0000000Z" />
      <EventRecordID>2999</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:18:43.0000000Z" />
      <EventRecordID>2998</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:30:23.0000000Z" />
      <EventRecordID>2997</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:29:14.0000000Z" />
      <EventRecordID>2996</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:20:34.0000000Z" />
      <EventRecordID>2995</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:37:13.0000000Z" />
      <EventRecordID>2994</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:12:55.0000000Z" />
      <EventRecordID>2993</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:13:22.0000000Z" />
      <EventRecordID>2992</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:37:02.0000000Z" />
      <EventRecordID>2991</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:45:23.0000000Z" />
      <EventRecordID>2990</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:04:36.0000000Z" />
      <EventRecordID>2989</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:32:33.0000000Z" />
      <EventRecordID>2988</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:01:43.0000000Z" />
      <EventRecordID>2987</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:34:53.0000000Z" />
      <EventRecordID>2986</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:02:30.0000000Z" />
      <EventRecordID>2985</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:41:30.0000000Z" />
      <EventRecordID>2984</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:14:03.0000000Z" />
      <EventRecordID>2983</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:18:58.0000000Z" />
      <EventRecordID>2982</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:45:47.0000000Z" />
      <EventRecordID>2981</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:13:33.0000000Z" />
      <EventRecordID>2980</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:03:21.0000000Z" />
      <EventRecordID>2979</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:00:45.0000000Z" />
      <EventRecordID>2978</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:56:59.0000000Z" />
      <EventRecordID>2977</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:39:48.0000000Z" />
      <EventRecordID>2976</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:03:10.0000000Z" />
      <EventRecordID>2975</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:20:09.0000000Z" />
      <EventRecordID>2974</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:12:40.0000000Z" />
      <EventRecordID>2973</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:11:50.0000000Z" />
      <EventRecordID>2972</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:10:37.0000000Z" />
      <EventRecordID>2971</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:39:43.0000000Z" />
      <EventRecordID>2970</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:57:32.0000000Z" />
      <EventRecordID>2969</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:40:26.0000000Z" />
      <EventRecordID>2968</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:34:08.0000000Z" />
      <EventRecordID>2967</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:40:05.0000000Z" />
      <EventRecordID>2966</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:13:55.0000000Z" />
      <EventRecordID>2965</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:15:22.0000000Z" />
      <EventRecordID>2964</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:06:09.0000000Z" />
      <EventRecordID>2963</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:42:09.0000000Z" />
      <EventRecordID>2962</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:00:51.0000000Z" />
      <EventRecordID>2961</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:05:57.0000000Z" />
      <EventRecordID>2960</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:31:03.0000000Z" />
      <EventRecordID>2959</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:22:14.0000000Z" />
      <EventRecordID>2958</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:26:15.0000000Z" />
      <EventRecordID>2957</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:58:39.0000000Z" />
      <EventRecordID>2956</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:05:01.0000000Z" />
      <EventRecordID>2955</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:31:56.0000000Z" />
      <EventRecordID>2954</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:55:57.0000000Z" />
      <EventRecordID>2953</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:56:31.0000000Z" />
      <EventRecordID>2952</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:06:28.0000000Z" />
      <EventRecordID>2951</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:24:15.0000000Z" />
      <EventRecordID>2950</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:03:58.0000000Z" />
      <EventRecordID>2949</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:17:45.0000000Z" />
      <EventRecordID>2948</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:43:59.0000000Z" />
      <EventRecordID>2947</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:17:15.0000000Z" />
      <EventRecordID>2946</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:38:43.0000000Z" />
      <EventRecordID>2945</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:56:19.0000000Z" />
      <EventRecordID>2944</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:43:00.0000000Z" />
      <EventRecordID>2943</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:54:13.0000000Z" />
      <EventRecordID>2942</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:54:30.0000000Z" />
      <EventRecordID>2941</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:25:40.0000000Z" />
      <EventRecordID>2940</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:42:14.0000000Z" />
      <EventRecordID>2939</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:43:11.0000000Z" />
      <EventRecordID>2938</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:11:54.0000000Z" />
      <EventRecordID>2937</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:36:46.0000000Z" />
      <EventRecordID>2936</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:21:56.0000000Z" />
      <EventRecordID>2935</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:51:36.0000000Z" />
      <EventRecordID>2934</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:08:00.0000000Z" />
      <EventRecordID>2933</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:14:56.0000000Z" />
      <EventRecordID>2932</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:08:00.0000000Z" />
      <EventRecordID>2931</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:07:58.0000000Z" />
      <EventRecordID>2930</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:18:35.0000000Z" />
      <EventRecordID>2929</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:28:55.0000000Z" />
      <EventRecordID>2928</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:55:26.0000000Z" />
      <EventRecordID>2927</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:01:03.0000000Z" />
      <EventRecordID>2926</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:25:12.0000000Z" />
      <EventRecordID>2925</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:33:28.0000000Z" />
      <EventRecordID>2924</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:25:35.0000000Z" />
      <EventRecordID>2923</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:34:11.0000000Z" />
      <EventRecordID>2922</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:26:31.0000000Z" />
      <EventRecordID>2921</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:06:47.0000000Z" />
      <EventRecordID>2920</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:54:25.0000000Z" />
      <EventRecordID>2919</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:29:01.0000000Z" />
      <EventRecordID>2918</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:23:24.0000000Z" />
      <EventRecordID>2917</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:32:18.0000000Z" />
      <EventRecordID>2916</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:01:49.0000000Z" />
      <EventRecordID>2915</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:47:45.0000000Z" />
      <EventRecordID>2914</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:45:35.0000000Z" />
      <EventRecordID>2913</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:58:49.0000000Z" />
      <EventRecordID>2912</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:16:31.0000000Z" />
      <EventRecordID>2911</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:58:04.0000000Z" />
      <EventRecordID>2910</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:43:26.0000000Z" />
      <EventRecordID>2909</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:46:47.0000000Z" />
      <EventRecordID>2908</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:31:39.0000000Z" />
      <EventRecordID>2907</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:45:28.0000000Z" />
      <EventRecordID>2906</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:52:18.0000000Z" />
      <EventRecordID>2905</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:44:29.0000000Z" />
      <EventRecordID>2904</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:11:10.0000000Z" />
      <EventRecordID>2903</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:08:17.0000000Z" />
      <EventRecordID>2902</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:14:02.0000000Z" />
      <EventRecordID>2901</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:50:00.0000000Z" />
      <EventRecordID>2900</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:21:06.0000000Z" />
      <EventRecordID>2899</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:07:09.0000000Z" />
      <EventRecordID>2898</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:02:04.0000000Z" />
      <EventRecordID>2897</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:32:18.0000000Z" />
      <EventRecordID>2896</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:43:46.0000000Z" />
      <EventRecordID>2895</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:34:59.0000000Z" />
      <EventRecordID>2894</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:10:00.0000000Z" />
      <EventRecordID>2893</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:49:52.0000000Z" />
      <EventRecordID>2892</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:10:24.0000000Z" />
      <EventRecordID>2891</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:40:28.0000000Z" />
      <EventRecordID>2890</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:15:03.0000000Z" />
      <EventRecordID>2889</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:27:31.0000000Z" />
      <EventRecordID>2888</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:15:20.0000000Z" />
      <EventRecordID>2887</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:03:13.0000000Z" />
      <EventRecordID>2886</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:04:43.0000000Z" />
      <EventRecordID>2885</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:50:57.0000000Z" />
      <EventRecordID>2884</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:14:58.0000000Z" />
      <EventRecordID>2883</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:37:29.0000000Z" />
      <EventRecordID>2882</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:29:58.0000000Z" />
      <EventRecordID>2881</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:56:41.0000000Z" />
      <EventRecordID>2880</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:46:38.0000000Z" />
      <EventRecordID>2879</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:51:43.0000000Z" />
      <EventRecordID>2878</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:36:10.0000000Z" />
      <EventRecordID>2877</EventRecordID>
      <Correlation />
      <Execution ProcessID="6020" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Edge" />
      <EventID Qualifiers="32768">256</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:07:34.0000000Z" />
      <EventRecordID>2876</EventRecordID>
      <Correlation />
      <Execution ProcessID="5436" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-21-3807162257-3739746291-1608561671-1106" />
    </System>
    <EventData>
      <Data>[5436:7288:0428/200913.675:INFO:extension_garbage_collector.cc(183)] Garbage collection for extensions on file thread is complete.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:12:33.0000000Z" />
      <EventRecordID>2875</EventRecordID>
      <Correlation />
      <Execution ProcessID="800" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:58:33.0000000Z" />
      <EventRecordID>2874</EventRecordID>
      <Correlation />
      <Execution ProcessID="800" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:49:06.0000000Z" />
      <EventRecordID>2873</EventRecordID>
      <Correlation />
      <Execution ProcessID="4332" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:54Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:02:00.0000000Z" />
      <EventRecordID>2872</EventRecordID>
      <Correlation />
      <Execution ProcessID="4332" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:30:58.0000000Z" />
      <EventRecordID>2871</EventRecordID>
      <Correlation />
      <Execution ProcessID="4908" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:28Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:35:28.0000000Z" />
      <EventRecordID>2870</EventRecordID>
      <Correlation />
      <Execution ProcessID="4908" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:14:31.0000000Z" />
      <EventRecordID>2869</EventRecordID>
      <Correlation />
      <Execution ProcessID="2944" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:28Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:47:01.0000000Z" />
      <EventRecordID>2868</EventRecordID>
      <Correlation />
      <Execution ProcessID="2944" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:17:36.0000000Z" />
      <EventRecordID>2867</EventRecordID>
      <Correlation />
      <Execution ProcessID="4720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:57:36.0000000Z" />
      <EventRecordID>2866</EventRecordID>
      <Correlation />
      <Execution ProcessID="4720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:00:07.0000000Z" />
      <EventRecordID>2865</EventRecordID>
      <Correlation />
      <Execution ProcessID="3460" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:37Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:18:46.0000000Z" />
      <EventRecordID>2864</EventRecordID>
      <Correlation />
      <Execution ProcessID="3460" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:47:01.0000000Z" />
      <EventRecordID>2863</EventRecordID>
      <Correlation />
      <Execution ProcessID="4840" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:57:41.0000000Z" />
      <EventRecordID>2862</EventRecordID>
      <Correlation />
      <Execution ProcessID="4840" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:15:14.0000000Z" />
      <EventRecordID>2861</EventRecordID>
      <Correlation />
      <Execution ProcessID="4460" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:13Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:05:00.0000000Z" />
      <EventRecordID>2860</EventRecordID>
      <Correlation />
      <Execution ProcessID="4460" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:29:54.0000000Z" />
      <EventRecordID>2859</EventRecordID>
      <Correlation />
      <Execution ProcessID="4364" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:14Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:42:58.0000000Z" />
      <EventRecordID>2858</EventRecordID>
      <Correlation />
      <Execution ProcessID="4364" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:01:21.0000000Z" />
      <EventRecordID>2857</EventRecordID>
      <Correlation />
      <Execution ProcessID="3932" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:54Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:25:27.0000000Z" />
      <EventRecordID>2856</EventRecordID>
      <Correlation />
      <Execution ProcessID="3932" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:40:51.0000000Z" />
      <EventRecordID>2855</EventRecordID>
      <Correlation />
      <Execution ProcessID="1112" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:32:00.0000000Z" />
      <EventRecordID>2854</EventRecordID>
      <Correlation />
      <Execution ProcessID="1112" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:32:09.0000000Z" />
      <EventRecordID>2853</EventRecordID>
      <Correlation />
      <Execution ProcessID="3700" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:24:36.0000000Z" />
      <EventRecordID>2852</EventRecordID>
      <Correlation />
      <Execution ProcessID="3700" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:24:23.0000000Z" />
      <EventRecordID>2851</EventRecordID>
      <Correlation />
      <Execution ProcessID="1772" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:13Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:04:01.0000000Z" />
      <EventRecordID>2850</EventRecordID>
      <Correlation />
      <Execution ProcessID="1772" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="edgeupdate" />
      <EventID Qualifiers="0">0</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:40:51.0000000Z" />
      <EventRecordID>2849</EventRecordID>
      <Correlation />
      <Execution ProcessID="2588" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Service stopped</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:08:53.0000000Z" />
      <EventRecordID>2848</EventRecordID>
      <Correlation />
      <Execution ProcessID="4292" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:52Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:25:58.0000000Z" />
      <EventRecordID>2847</EventRecordID>
      <Correlation />
      <Execution ProcessID="4292" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:17:21.0000000Z" />
      <EventRecordID>2846</EventRecordID>
      <Correlation />
      <Execution ProcessID="3604" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:38Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:51:05.0000000Z" />
      <EventRecordID>2845</EventRecordID>
      <Correlation />
      <Execution ProcessID="3604" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:43:19.0000000Z" />
      <EventRecordID>2844</EventRecordID>
      <Correlation />
      <Execution ProcessID="4576" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:52Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:54:07.0000000Z" />
      <EventRecordID>2843</EventRecordID>
      <Correlation />
      <Execution ProcessID="4576" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:45:38.0000000Z" />
      <EventRecordID>2842</EventRecordID>
      <Correlation />
      <Execution ProcessID="4296" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:17Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:32:21.0000000Z" />
      <EventRecordID>2841</EventRecordID>
      <Correlation />
      <Execution ProcessID="4296" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:48:47.0000000Z" />
      <EventRecordID>2840</EventRecordID>
      <Correlation />
      <Execution ProcessID="4932" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:52Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:33:50.0000000Z" />
      <EventRecordID>2839</EventRecordID>
      <Correlation />
      <Execution ProcessID="4932" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:49:43.0000000Z" />
      <EventRecordID>2838</EventRecordID>
      <Correlation />
      <Execution ProcessID="2056" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:04Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:51:36.0000000Z" />
      <EventRecordID>2837</EventRecordID>
      <Correlation />
      <Execution ProcessID="2056" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:27:10.0000000Z" />
      <EventRecordID>2836</EventRecordID>
      <Correlation />
      <Execution ProcessID="5028" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:47Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:34:34.0000000Z" />
      <EventRecordID>2835</EventRecordID>
      <Correlation />
      <Execution ProcessID="5028" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:14:56.0000000Z" />
      <EventRecordID>2834</EventRecordID>
      <Correlation />
      <Execution ProcessID="2256" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:51Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:53:22.0000000Z" />
      <EventRecordID>2833</EventRecordID>
      <Correlation />
      <Execution ProcessID="2256" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:27:26.0000000Z" />
      <EventRecordID>2832</EventRecordID>
      <Correlation />
      <Execution ProcessID="4276" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:50Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:12:45.0000000Z" />
      <EventRecordID>2831</EventRecordID>
      <Correlation />
      <Execution ProcessID="4276" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:29:42.0000000Z" />
      <EventRecordID>2830</EventRecordID>
      <Correlation />
      <Execution ProcessID="592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:51Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:06:55.0000000Z" />
      <EventRecordID>2829</EventRecordID>
      <Correlation />
      <Execution ProcessID="592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:16:00.0000000Z" />
      <EventRecordID>2828</EventRecordID>
      <Correlation />
      <Execution ProcessID="1632" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:01Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:39:54.0000000Z" />
      <EventRecordID>2827</EventRecordID>
      <Correlation />
      <Execution ProcessID="1632" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:05:04.0000000Z" />
      <EventRecordID>2826</EventRecordID>
      <Correlation />
      <Execution ProcessID="2672" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:51Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:24:11.0000000Z" />
      <EventRecordID>2825</EventRecordID>
      <Correlation />
      <Execution ProcessID="2672" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:26:49.0000000Z" />
      <EventRecordID>2824</EventRecordID>
      <Correlation />
      <Execution ProcessID="1224" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:27Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:24:13.0000000Z" />
      <EventRecordID>2823</EventRecordID>
      <Correlation />
      <Execution ProcessID="1224" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:14:20.0000000Z" />
      <EventRecordID>2822</EventRecordID>
      <Correlation />
      <Execution ProcessID="3860" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:51Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:54:11.0000000Z" />
      <EventRecordID>2821</EventRecordID>
      <Correlation />
      <Execution ProcessID="3860" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:29:48.0000000Z" />
      <EventRecordID>2820</EventRecordID>
      <Correlation />
      <Execution ProcessID="4152" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:59Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:19:57.0000000Z" />
      <EventRecordID>2819</EventRecordID>
      <Correlation />
      <Execution ProcessID="4152" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:51:31.0000000Z" />
      <EventRecordID>2818</EventRecordID>
      <Correlation />
      <Execution ProcessID="4580" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:50Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:18:18.0000000Z" />
      <EventRecordID>2817</EventRecordID>
      <Correlation />
      <Execution ProcessID="4580" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:44:06.0000000Z" />
      <EventRecordID>2816</EventRecordID>
      <Correlation />
      <Execution ProcessID="524" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:03Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:26:58.0000000Z" />
      <EventRecordID>2815</EventRecordID>
      <Correlation />
      <Execution ProcessID="524" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:58:30.0000000Z" />
      <EventRecordID>2814</EventRecordID>
      <Correlation />
      <Execution ProcessID="4624" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:40Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:45:10.0000000Z" />
      <EventRecordID>2813</EventRecordID>
      <Correlation />
      <Execution ProcessID="4624" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SceCli" />
      <EventID Qualifiers="16384">1704</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:49:08.0000000Z" />
      <EventRecordID>2812</EventRecordID>
      <Correlation />
      <Execution ProcessID="2648" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>
      </Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:24:11.0000000Z" />
      <EventRecordID>2811</EventRecordID>
      <Correlation />
      <Execution ProcessID="3868" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:50Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:49:10.0000000Z" />
      <EventRecordID>2810</EventRecordID>
      <Correlation />
      <Execution ProcessID="3868" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:01:18.0000000Z" />
      <EventRecordID>2809</EventRecordID>
      <Correlation />
      <Execution ProcessID="5100" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:50Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:26:22.0000000Z" />
      <EventRecordID>2808</EventRecordID>
      <Correlation />
      <Execution ProcessID="5100" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:20:58.0000000Z" />
      <EventRecordID>2807</EventRecordID>
      <Correlation />
      <Execution ProcessID="3500" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:05Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1033</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:01:47.0000000Z" />
      <EventRecordID>2806</EventRecordID>
      <Correlation />
      <Execution ProcessID="3500" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>(Security-SPP-Reserved-EnableNotificationMode) </Data>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>aa708397-8618-42de-b120-a44190ef456d</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:15:04.0000000Z" />
      <EventRecordID>2805</EventRecordID>
      <Correlation />
      <Execution ProcessID="3500" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Security-SPP-Reserved-LicenseProperties</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:51:37.0000000Z" />
      <EventRecordID>2804</EventRecordID>
      <Correlation />
      <Execution ProcessID="3500" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>AAD-AddDeviceJoinUserToAdminGroup-Policy</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:03:59.0000000Z" />
      <EventRecordID>2803</EventRecordID>
      <Correlation />
      <Execution ProcessID="3500" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:13:29.0000000Z" />
      <EventRecordID>2802</EventRecordID>
      <Correlation />
      <Execution ProcessID="3548" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:01:06.0000000Z" />
      <EventRecordID>2801</EventRecordID>
      <Correlation />
      <Execution ProcessID="3548" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="ESENT" />
      <EventID Qualifiers="0">325</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:11:40.0000000Z" />
      <EventRecordID>2800</EventRecordID>
      <Correlation />
      <Execution ProcessID="676" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>svchost</Data>
      <Data>676,D,35,0</Data>
      <Data>DS_Token_DB: </Data>
      <Data>1</Data>
      <Data>C:\WINDOWS\system32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat</Data>
      <Data>0</Data>
      <Data>
[1] 0.000388 +J(0) +M(C:0K, Fs:1, WS:4K # 4K, PF:4K # 4K, P:4K)
[2] 0.006861 -0.000829 (1) WT +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:3480/2) +M(C:0K, Fs:3, WS:12K # 12K, PF:0K # 0K, P:0K)
[3] 0.017701 -0.000242 (4) WT +J(0) +M(C:0K, Fs:13, WS:44K # 48K, PF:28K # 32K, P:28K)
[4] 0.024294 -0.020328 (1) WT +J(0) +M(C:0K, Fs:59, WS:236K # 232K, PF:92K # 88K, P:92K)
[5] 0.007963 -0.001693 (3) WT +J(CM:0, PgRf:3, Rd:0/0, Dy:3/6, Lg:122/4) +M(C:8K, Fs:55, WS:216K # 216K, PF:164K # 168K, P:164K)
[6] 0.026332 -0.015642 (4) WT +J(CM:0, PgRf:259, Rd:0/0, Dy:16/440, Lg:28550/479) +M(C:64K, Fs:104, WS:416K # 416K, PF:552K # 552K, P:552K)
[7] 0.005253 -0.001393 (3) WT +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:4096/3) +M(C:0K, Fs:4, WS:12K # 12K, PF:0K # 0K, P:0K)
[8] 0.000015 +J(0)
[9] 0.036180 -0.032334 (5) WT +J(0) +M(C:-40K, Fs:7, WS:-16K # 16K, PF:24K # 60K, P:24K)
[10] 0.066923 -0.015470 (11) CM -0.023135 (24) WT +J(CM:11, PgRf:428, Rd:0/11, Dy:9/107, Lg:17039/155) +M(C:16K, Fs:57, WS:208K # 180K, PF:100K # 64K, P:100K)
[11] 0.000012 +J(0).</Data>
      <Data>0 0</Data>
      <Data>lgposCreate = 00000001:0001:0268,
dbv = 1568.300.620 (9620)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="ESENT" />
      <EventID Qualifiers="0">105</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:55:45.0000000Z" />
      <EventRecordID>2799</EventRecordID>
      <Correlation />
      <Execution ProcessID="676" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>svchost</Data>
      <Data>676,D,0,0</Data>
      <Data>DS_Token_DB: </Data>
      <Data>0</Data>
      <Data>0.059</Data>
      <Data>
[1] 0.000940 +J(0) +M(C:0K, Fs:161, WS:628K # 628K, PF:2564K # 2568K, P:2564K)
[2] 0.002460 +J(0) +M(C:8K, Fs:210, WS:828K # 828K, PF:1240K # 1236K, P:1240K)
[3] 0.000052 +J(0) +M(C:0K, Fs:2, WS:4K # 4K, PF:68K # 68K, P:68K)
[4] 0.000340 +J(0) +M(C:0K, Fs:35, WS:140K # 140K, PF:168K # 168K, P:168K)
[5] 0.004283 +J(0) +M(C:0K, Fs:12, WS:48K # 48K, PF:20K # 20K, P:20K)
[6] 0.004086 -0.000009 (1) WT +J(0) +M(C:0K, Fs:30, WS:120K # 120K, PF:12K # 12K, P:12K)
[7] -
[8] -
[9] -
[10] -
[11] -
[12] -
[13] 0.036504 -0.002401 (6) WT +J(CM:0, PgRf:0, Rd:0/0, Dy:0/0, Lg:616/1) +M(C:0K, Fs:106, WS:360K # 400K, PF:20K # 80K, P:20K)
[14] 0.000062 +J(0) +M(C:0K, Fs:3, WS:12K # 0K, PF:8K # 0K, P:8K)
[15] 0.000063 +J(0) +M(C:0K, Fs:17, WS:68K # 40K, PF:64K # 12K, P:64K)
[16] 0.009756 -0.000880 (3) WT +J(0) +M(C:0K, Fs:4, WS:8K # 12K, PF:0K # 4K, P:0K).</Data>
      <Data>RBSOn = 0
</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="ESENT" />
      <EventID Qualifiers="0">102</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:31:08.0000000Z" />
      <EventRecordID>2798</EventRecordID>
      <Correlation />
      <Execution ProcessID="676" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>svchost</Data>
      <Data>676,P,98,0</Data>
      <Data>DS_Token_DB: </Data>
      <Data>0</Data>
      <Data>10</Data>
      <Data>00</Data>
      <Data>26100</Data>
      <Data>0000</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:21:33.0000000Z" />
      <EventRecordID>2797</EventRecordID>
      <Correlation />
      <Execution ProcessID="1304" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:49Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:32:48.0000000Z" />
      <EventRecordID>2796</EventRecordID>
      <Correlation />
      <Execution ProcessID="1304" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:56:43.0000000Z" />
      <EventRecordID>2795</EventRecordID>
      <Correlation />
      <Execution ProcessID="1820" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:49Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:55:06.0000000Z" />
      <EventRecordID>2794</EventRecordID>
      <Correlation />
      <Execution ProcessID="1820" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:58:49.0000000Z" />
      <EventRecordID>2793</EventRecordID>
      <Correlation />
      <Execution ProcessID="3696" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:38Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:25:41.0000000Z" />
      <EventRecordID>2792</EventRecordID>
      <Correlation />
      <Execution ProcessID="3696" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:57:04.0000000Z" />
      <EventRecordID>2791</EventRecordID>
      <Correlation />
      <Execution ProcessID="2560" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:47Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:28:07.0000000Z" />
      <EventRecordID>2790</EventRecordID>
      <Correlation />
      <Execution ProcessID="2560" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:36:25.0000000Z" />
      <EventRecordID>2789</EventRecordID>
      <Correlation />
      <Execution ProcessID="3504" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:14Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:09:03.0000000Z" />
      <EventRecordID>2788</EventRecordID>
      <Correlation />
      <Execution ProcessID="3504" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:42:06.0000000Z" />
      <EventRecordID>2787</EventRecordID>
      <Correlation />
      <Execution ProcessID="3472" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:49Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:00:06.0000000Z" />
      <EventRecordID>2786</EventRecordID>
      <Correlation />
      <Execution ProcessID="3472" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:49:37.0000000Z" />
      <EventRecordID>2785</EventRecordID>
      <Correlation />
      <Execution ProcessID="4608" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:35Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:23:10.0000000Z" />
      <EventRecordID>2784</EventRecordID>
      <Correlation />
      <Execution ProcessID="4608" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:45:27.0000000Z" />
      <EventRecordID>2783</EventRecordID>
      <Correlation />
      <Execution ProcessID="4432" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:49Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:01:02.0000000Z" />
      <EventRecordID>2782</EventRecordID>
      <Correlation />
      <Execution ProcessID="4432" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:26:02.0000000Z" />
      <EventRecordID>2781</EventRecordID>
      <Correlation />
      <Execution ProcessID="4468" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:41Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:23:45.0000000Z" />
      <EventRecordID>2780</EventRecordID>
      <Correlation />
      <Execution ProcessID="4468" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:02:28.0000000Z" />
      <EventRecordID>2779</EventRecordID>
      <Correlation />
      <Execution ProcessID="2952" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:48Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:33:31.0000000Z" />
      <EventRecordID>2778</EventRecordID>
      <Correlation />
      <Execution ProcessID="2952" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:03:48.0000000Z" />
      <EventRecordID>2777</EventRecordID>
      <Correlation />
      <Execution ProcessID="1560" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:48Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:05:07.0000000Z" />
      <EventRecordID>2776</EventRecordID>
      <Correlation />
      <Execution ProcessID="1560" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:33:19.0000000Z" />
      <EventRecordID>2775</EventRecordID>
      <Correlation />
      <Execution ProcessID="1084" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:57Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:52:56.0000000Z" />
      <EventRecordID>2774</EventRecordID>
      <Correlation />
      <Execution ProcessID="1084" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:22:53.0000000Z" />
      <EventRecordID>2773</EventRecordID>
      <Correlation />
      <Execution ProcessID="4580" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:58Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:49:01.0000000Z" />
      <EventRecordID>2772</EventRecordID>
      <Correlation />
      <Execution ProcessID="4580" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:03:12.0000000Z" />
      <EventRecordID>2771</EventRecordID>
      <Correlation />
      <Execution ProcessID="3948" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:48Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:45:05.0000000Z" />
      <EventRecordID>2770</EventRecordID>
      <Correlation />
      <Execution ProcessID="3948" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:37:32.0000000Z" />
      <EventRecordID>2769</EventRecordID>
      <Correlation />
      <Execution ProcessID="4272" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:40Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:28:06.0000000Z" />
      <EventRecordID>2768</EventRecordID>
      <Correlation />
      <Execution ProcessID="4272" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:47:45.0000000Z" />
      <EventRecordID>2767</EventRecordID>
      <Correlation />
      <Execution ProcessID="3412" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:48Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:55:59.0000000Z" />
      <EventRecordID>2766</EventRecordID>
      <Correlation />
      <Execution ProcessID="3412" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:28:07.0000000Z" />
      <EventRecordID>2765</EventRecordID>
      <Correlation />
      <Execution ProcessID="632" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:47Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:25:38.0000000Z" />
      <EventRecordID>2764</EventRecordID>
      <Correlation />
      <Execution ProcessID="632" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:44:18.0000000Z" />
      <EventRecordID>2763</EventRecordID>
      <Correlation />
      <Execution ProcessID="1492" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:43Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:00:55.0000000Z" />
      <EventRecordID>2762</EventRecordID>
      <Correlation />
      <Execution ProcessID="1492" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:02:19.0000000Z" />
      <EventRecordID>2761</EventRecordID>
      <Correlation />
      <Execution ProcessID="3252" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:47Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:31:47.0000000Z" />
      <EventRecordID>2760</EventRecordID>
      <Correlation />
      <Execution ProcessID="3252" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:08:20.0000000Z" />
      <EventRecordID>2759</EventRecordID>
      <Correlation />
      <Execution ProcessID="2988" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:57:14Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:14:13.0000000Z" />
      <EventRecordID>2758</EventRecordID>
      <Correlation />
      <Execution ProcessID="2988" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="edgeupdate" />
      <EventID Qualifiers="0">0</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:51:31.0000000Z" />
      <EventRecordID>2757</EventRecordID>
      <Correlation />
      <Execution ProcessID="2808" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Service stopped</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="edgeupdate" />
      <EventID Qualifiers="0">0</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:51:33.0000000Z" />
      <EventRecordID>2756</EventRecordID>
      <Correlation />
      <Execution ProcessID="3536" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Service stopped</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:39:03.0000000Z" />
      <EventRecordID>2755</EventRecordID>
      <Correlation />
      <Execution ProcessID="1392" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:47Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:12:30.0000000Z" />
      <EventRecordID>2754</EventRecordID>
      <Correlation />
      <Execution ProcessID="1392" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:48:26.0000000Z" />
      <EventRecordID>2753</EventRecordID>
      <Correlation />
      <Execution ProcessID="4204" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:43Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:07:58.0000000Z" />
      <EventRecordID>2752</EventRecordID>
      <Correlation />
      <Execution ProcessID="4204" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:00:25.0000000Z" />
      <EventRecordID>2751</EventRecordID>
      <Correlation />
      <Execution ProcessID="280" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:46Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:50:01.0000000Z" />
      <EventRecordID>2750</EventRecordID>
      <Correlation />
      <Execution ProcessID="280" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:46:20.0000000Z" />
      <EventRecordID>2749</EventRecordID>
      <Correlation />
      <Execution ProcessID="4092" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:56Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:42:33.0000000Z" />
      <EventRecordID>2748</EventRecordID>
      <Correlation />
      <Execution ProcessID="4092" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:45:12.0000000Z" />
      <EventRecordID>2747</EventRecordID>
      <Correlation />
      <Execution ProcessID="5000" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:46Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:39:00.0000000Z" />
      <EventRecordID>2746</EventRecordID>
      <Correlation />
      <Execution ProcessID="5000" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:35:54.0000000Z" />
      <EventRecordID>2745</EventRecordID>
      <Correlation />
      <Execution ProcessID="2060" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:24Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:42:57.0000000Z" />
      <EventRecordID>2744</EventRecordID>
      <Correlation />
      <Execution ProcessID="2060" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:03:26.0000000Z" />
      <EventRecordID>2743</EventRecordID>
      <Correlation />
      <Execution ProcessID="2564" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:46Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:52:42.0000000Z" />
      <EventRecordID>2742</EventRecordID>
      <Correlation />
      <Execution ProcessID="2564" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:49:02.0000000Z" />
      <EventRecordID>2741</EventRecordID>
      <Correlation />
      <Execution ProcessID="1104" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:49Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:50:49.0000000Z" />
      <EventRecordID>2740</EventRecordID>
      <Correlation />
      <Execution ProcessID="1104" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:53:55.0000000Z" />
      <EventRecordID>2739</EventRecordID>
      <Correlation />
      <Execution ProcessID="4668" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:46Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:49:02.0000000Z" />
      <EventRecordID>2738</EventRecordID>
      <Correlation />
      <Execution ProcessID="4668" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:37:46.0000000Z" />
      <EventRecordID>2737</EventRecordID>
      <Correlation />
      <Execution ProcessID="1300" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:48Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:45:10.0000000Z" />
      <EventRecordID>2736</EventRecordID>
      <Correlation />
      <Execution ProcessID="1300" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:56:50.0000000Z" />
      <EventRecordID>2735</EventRecordID>
      <Correlation />
      <Execution ProcessID="4756" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:28Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:21:36.0000000Z" />
      <EventRecordID>2734</EventRecordID>
      <Correlation />
      <Execution ProcessID="4756" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:26:48.0000000Z" />
      <EventRecordID>2733</EventRecordID>
      <Correlation />
      <Execution ProcessID="4924" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:45Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:05:35.0000000Z" />
      <EventRecordID>2732</EventRecordID>
      <Correlation />
      <Execution ProcessID="4924" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:44:43.0000000Z" />
      <EventRecordID>2731</EventRecordID>
      <Correlation />
      <Execution ProcessID="4720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:26Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:54:38.0000000Z" />
      <EventRecordID>2730</EventRecordID>
      <Correlation />
      <Execution ProcessID="4720" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:29:31.0000000Z" />
      <EventRecordID>2729</EventRecordID>
      <Correlation />
      <Execution ProcessID="3368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:42Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:38:04.0000000Z" />
      <EventRecordID>2728</EventRecordID>
      <Correlation />
      <Execution ProcessID="3368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:29:11.0000000Z" />
      <EventRecordID>2727</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:45Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:40:34.0000000Z" />
      <EventRecordID>2726</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:49:48.0000000Z" />
      <EventRecordID>2725</EventRecordID>
      <Correlation />
      <Execution ProcessID="5104" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:32:08.0000000Z" />
      <EventRecordID>2724</EventRecordID>
      <Correlation />
      <Execution ProcessID="5104" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:06:20.0000000Z" />
      <EventRecordID>2723</EventRecordID>
      <Correlation />
      <Execution ProcessID="1120" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:45Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:24:29.0000000Z" />
      <EventRecordID>2722</EventRecordID>
      <Correlation />
      <Execution ProcessID="1120" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:40:54.0000000Z" />
      <EventRecordID>2721</EventRecordID>
      <Correlation />
      <Execution ProcessID="5028" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:44Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:33:46.0000000Z" />
      <EventRecordID>2720</EventRecordID>
      <Correlation />
      <Execution ProcessID="5028" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:37:36.0000000Z" />
      <EventRecordID>2719</EventRecordID>
      <Correlation />
      <Execution ProcessID="3604" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:32Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:05:03.0000000Z" />
      <EventRecordID>2718</EventRecordID>
      <Correlation />
      <Execution ProcessID="3604" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:01:17.0000000Z" />
      <EventRecordID>2717</EventRecordID>
      <Correlation />
      <Execution ProcessID="512" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:32Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:08:47.0000000Z" />
      <EventRecordID>2716</EventRecordID>
      <Correlation />
      <Execution ProcessID="512" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:11:44.0000000Z" />
      <EventRecordID>2715</EventRecordID>
      <Correlation />
      <Execution ProcessID="4860" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">EXE\PC01$</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(219ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:44:26.0000000Z" />
      <EventRecordID>2714</EventRecordID>
      <Correlation />
      <Execution ProcessID="588" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:44Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:38:39.0000000Z" />
      <EventRecordID>2713</EventRecordID>
      <Correlation />
      <Execution ProcessID="588" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:45:58.0000000Z" />
      <EventRecordID>2712</EventRecordID>
      <Correlation />
      <Execution ProcessID="3548" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:46:50.0000000Z" />
      <EventRecordID>2711</EventRecordID>
      <Correlation />
      <Execution ProcessID="4068" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:21Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:49:45.0000000Z" />
      <EventRecordID>2710</EventRecordID>
      <Correlation />
      <Execution ProcessID="4068" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:19:59.0000000Z" />
      <EventRecordID>2709</EventRecordID>
      <Correlation />
      <Execution ProcessID="2204" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:53Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:57:41.0000000Z" />
      <EventRecordID>2708</EventRecordID>
      <Correlation />
      <Execution ProcessID="3548" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
      <EventID Qualifiers="16384">1003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:12:22.0000000Z" />
      <EventRecordID>2707</EventRecordID>
      <Correlation />
      <Execution ProcessID="2636" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data Name="ExtraInfo">
      </Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">1</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:21:17.0000000Z" />
      <EventRecordID>2706</EventRecordID>
      <Correlation />
      <Execution ProcessID="3548" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:41:43.0000000Z" />
      <EventRecordID>2705</EventRecordID>
      <Correlation />
      <Execution ProcessID="2204" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">900</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:07:28.0000000Z" />
      <EventRecordID>2704</EventRecordID>
      <Correlation />
      <Execution ProcessID="2204" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>&lt;explicit&gt;</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="edgeupdate" />
      <EventID Qualifiers="0">0</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:20:29.0000000Z" />
      <EventRecordID>2703</EventRecordID>
      <Correlation />
      <Execution ProcessID="1476" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Service stopped</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:38:40.0000000Z" />
      <EventRecordID>2702</EventRecordID>
      <Correlation />
      <Execution ProcessID="5056" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:57Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:46:14.0000000Z" />
      <EventRecordID>2701</EventRecordID>
      <Correlation />
      <Execution ProcessID="5056" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:38:40.0000000Z" />
      <EventRecordID>2700</EventRecordID>
      <Correlation ActivityID="{cfaf9930-b7d3-0001-739e-afcfd3b7db01}" />
      <Execution ProcessID="3180" ThreadID="3432" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv1</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:22:28.0000000Z" />
      <EventRecordID>2699</EventRecordID>
      <Correlation ActivityID="{cfaf9930-b7d3-0001-739e-afcfd3b7db01}" />
      <Execution ProcessID="3180" ThreadID="3432" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv1</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:39:23.0000000Z" />
      <EventRecordID>2698</EventRecordID>
      <Correlation />
      <Execution ProcessID="3180" ThreadID="4896" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv1</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:16:39.0000000Z" />
      <EventRecordID>2697</EventRecordID>
      <Correlation ActivityID="{cfaf9930-b7d3-0001-739e-afcfd3b7db01}" />
      <Execution ProcessID="3180" ThreadID="4888" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:48:56.0000000Z" />
      <EventRecordID>2696</EventRecordID>
      <Correlation ActivityID="{cfaf9930-b7d3-0001-739e-afcfd3b7db01}" />
      <Execution ProcessID="3180" ThreadID="4888" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>63</EventID>
      <Version>2</Version>
      <Level>3</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:40:59.0000000Z" />
      <EventRecordID>2695</EventRecordID>
      <Correlation />
      <Execution ProcessID="3180" ThreadID="4896" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <UserData>
      <data_0x8000003F xmlns="http://manifests.microsoft.com/win/2006/windows/WMI">
        <Provider>DMWmiBridgeProv</Provider>
        <Namespace>root\cimv2\mdm\dmmap</Namespace>
      </data_0x8000003F>
    </UserData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>5617</EventID>
      <Version>2</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:16:29.0000000Z" />
      <EventRecordID>2694</EventRecordID>
      <Correlation />
      <Execution ProcessID="3180" ThreadID="3468" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">903</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:53:33.0000000Z" />
      <EventRecordID>2693</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:30:47.0000000Z" />
      <EventRecordID>2692</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-04-29T00:23:45Z</Data>
      <Data>TBL</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:36:44.0000000Z" />
      <EventRecordID>2691</EventRecordID>
      <Correlation />
      <Execution ProcessID="2644" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">EXE\PC01$</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(78ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:35:39.0000000Z" />
      <EventRecordID>2690</EventRecordID>
      <Correlation />
      <Execution ProcessID="2644" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">Local system</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(1313ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:17:50.0000000Z" />
      <EventRecordID>2689</EventRecordID>
      <Correlation />
      <Execution ProcessID="2644" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">EXE\PC01$</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(391ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">8230</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:32:09.0000000Z" />
      <EventRecordID>2688</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Security-SPP-Action-StateData (REG_SZ) =AppId=55c92734-d682-4d71-983e-d6ec3f16059f;GraceEndDate=2025/07/26:18:57:15;LastConsumptionReason=0x4004fc04;LastNotificationId=Cleanup;LicenseState=SL_LICENSING_STATUS_LICENSED;PartialProductKey=M4K7D;ProductKeyType=Retail:TB:Eval;SkuId=aa708397-8618-42de-b120-a44190ef456d;ruleId=379cccfb-d4e0-48fe-b0f2-0136097be147;uxDifferentiator=TIMEBASED_EVAL</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16388</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:49:52.0000000Z" />
      <EventRecordID>2687</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-04-28T00:24:15Z</Data>
      <Data>2025-04-28T00:24:15Z</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">902</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:25:04.0000000Z" />
      <EventRecordID>2686</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>10.0.26100.3624</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="32768">1037</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:09:46.0000000Z" />
      <EventRecordID>2685</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>validity</Data>
      <Data>129273</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:22:39.0000000Z" />
      <EventRecordID>2684</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>
1: 399f0697-886b-4881-894c-4ff6c52e7d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
2: aa708397-8618-42de-b120-a44190ef456d, 1, 0 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 90 129273)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]

</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1033</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:30:46.0000000Z" />
      <EventRecordID>2683</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>(Security-SPP-Reserved-EnableNotificationMode) </Data>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>aa708397-8618-42de-b120-a44190ef456d</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:26:15.0000000Z" />
      <EventRecordID>2682</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Security-SPP-Reserved-LicenseProperties</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:35:24.0000000Z" />
      <EventRecordID>2681</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>AAD-AddDeviceJoinUserToAdminGroup-Policy</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:46:00.0000000Z" />
      <EventRecordID>2680</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) UL oob License (Private)</Data>
      <Data>bedb0f8e-a8df-4f3f-b59e-4601adc3e90d</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:50:12.0000000Z" />
      <EventRecordID>2679</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) UL oob License (Public)</Data>
      <Data>9c778e96-9bff-49f9-8e6f-677c5dc22617</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:42:06.0000000Z" />
      <EventRecordID>2678</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) Publishing License (Private)</Data>
      <Data>320e5cce-fab7-4a57-bda9-f5da6c070b66</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:53:11.0000000Z" />
      <EventRecordID>2677</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) Publishing License (Public)</Data>
      <Data>935af2ce-7681-482c-a6cb-116fa7d0b6e6</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:42:45.0000000Z" />
      <EventRecordID>2676</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) IoTEnterpriseSEval Product PPD License</Data>
      <Data>94645a72-6dce-22b0-4ea5-8ee04147d0ea</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:27:39.0000000Z" />
      <EventRecordID>2675</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>DefaultPpd-IoTEnterpriseSEval Component PPD License</Data>
      <Data>8c9f298e-3082-9e8c-842b-d80d5592bebc</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:10:13.0000000Z" />
      <EventRecordID>2674</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) UL oob License (Private)</Data>
      <Data>9ec93087-b6f5-4d92-be25-a0ef10637732</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:44:09.0000000Z" />
      <EventRecordID>2673</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) UL oob License (Public)</Data>
      <Data>7e0027e9-6a4c-4f3d-b456-a09021bc853c</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:17:55.0000000Z" />
      <EventRecordID>2672</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) Publishing License (Private)</Data>
      <Data>e801cb5e-010e-479c-ae38-f33066d6669b</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:27:08.0000000Z" />
      <EventRecordID>2671</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) Publishing License (Public)</Data>
      <Data>0990f520-1940-4285-b98b-b5de7f9b4fbe</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:22:33.0000000Z" />
      <EventRecordID>2670</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows(R) EnterpriseSEval Product PPD License</Data>
      <Data>28def255-fa82-a64a-169a-2940d79cc443</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:52:20.0000000Z" />
      <EventRecordID>2669</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>DefaultPpd-EnterpriseSEval Component PPD License</Data>
      <Data>208dc3eb-7e98-d336-65f7-b495f015e295</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1004</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:00:59.0000000Z" />
      <EventRecordID>2668</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>XrML 2.1 License - Product Key Configuration</Data>
      <Data>06a4dd30-84b7-4fd2-b859-f1eddb0858f5</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1066</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:41:23.0000000Z" />
      <EventRecordID>2667</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:51:27.0000000Z" />
      <EventRecordID>2666</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">900</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:29:08.0000000Z" />
      <EventRecordID>2665</EventRecordID>
      <Correlation />
      <Execution ProcessID="3592" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>TriggerStarted:6</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>5615</EventID>
      <Version>2</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:05:36.0000000Z" />
      <EventRecordID>2664</EventRecordID>
      <Correlation />
      <Execution ProcessID="3180" ThreadID="3468" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}" />
      <EventID>1531</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:04:37.0000000Z" />
      <EventRecordID>2663</EventRecordID>
      <Correlation />
      <Execution ProcessID="1988" ThreadID="1552" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}" />
      <EventID>1532</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:28:32.0000000Z" />
      <EventRecordID>2662</EventRecordID>
      <Correlation />
      <Execution ProcessID="1820" ThreadID="2004" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CAPI2" Guid="{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}" EventSourceName="Microsoft-Windows-CAPI2" />
      <EventID Qualifiers="0">4097</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8080000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:31:23.0000000Z" />
      <EventRecordID>2661</EventRecordID>
      <Correlation />
      <Execution ProcessID="1116" ThreadID="7404" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>CN=DigiCert Trusted Root G4, OU=www.digicert.com, O=DigiCert Inc, C=US</Data>
      <Data>DDFB16CD4931C973A2037D3FC83A4D7D775D05E4</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:48:46.0000000Z" />
      <EventRecordID>2660</EventRecordID>
      <Correlation />
      <Execution ProcessID="796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:06:15.0000000Z" />
      <EventRecordID>2659</EventRecordID>
      <Correlation />
      <Execution ProcessID="796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>WSearch</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:55:01.0000000Z" />
      <EventRecordID>2658</EventRecordID>
      <Correlation />
      <Execution ProcessID="2052" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:37Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:30:20.0000000Z" />
      <EventRecordID>2657</EventRecordID>
      <Correlation />
      <Execution ProcessID="2052" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:29:59.0000000Z" />
      <EventRecordID>2656</EventRecordID>
      <Correlation />
      <Execution ProcessID="4784" ThreadID="2724" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">1645312067461807022</Data>
      <Data Name="BucketType">5</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.abe78833-bd16-4794-a6b6-8a31ad6467a8.tmp.WERInternalMetadata.xml</Data>
      <Data Name="StorePath">\\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.26100.3764__5e199f9f9d7e17f91d343fe6804ae56d4d4ab8dc_00000000_ced858d5-89e8-4f15-9901-db656a240044</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">ced858d5-89e8-4f15-9901-db656a240044</Data>
      <Data Name="ReportStatus">268435456</Data>
      <Data Name="HashedBucket">eff1b3c91036ad4dc6d5529badb97bae</Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:47:30.0000000Z" />
      <EventRecordID>2655</EventRecordID>
      <Correlation />
      <Execution ProcessID="4124" ThreadID="2984" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">
      </Data>
      <Data Name="BucketType">0</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
\\?\C:\Windows\Logs\CBS\CBS.log
\\?\C:\Windows\Logs\CBS\CbsPersist_20250427234902.log
\\?\C:\Windows\Logs\CBS\CbsPersist_20250427220601.cab
\\?\C:\Windows\Logs\CBS\CbsPersist_20250427211157.cab
\\?\C:\Windows\Logs\CBS\container.etl
\\?\C:\WINDOWS\servicing\Sessions\Sessions.xml
\\?\C:\WINDOWS\system32\LogFiles\Scm\SCM.EVM
\\?\C:\WINDOWS\Logs\Cbs\FilterList.log</Data>
      <Data Name="StorePath">NULL</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">ced858d5-89e8-4f15-9901-db656a240044</Data>
      <Data Name="ReportStatus">262148</Data>
      <Data Name="HashedBucket">
      </Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:51:37.0000000Z" />
      <EventRecordID>2654</EventRecordID>
      <Correlation />
      <Execution ProcessID="4372" ThreadID="6952" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">
      </Data>
      <Data Name="BucketType">0</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
      </Data>
      <Data Name="StorePath">\\?\C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_10.0.26100.3764__5e199f9f9d7e17f91d343fe6804ae56d4d4ab8dc_00000000_ced858d5-89e8-4f15-9901-db656a240044</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">ced858d5-89e8-4f15-9901-db656a240044</Data>
      <Data Name="ReportStatus">4</Data>
      <Data Name="HashedBucket">
      </Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:10:58.0000000Z" />
      <EventRecordID>2653</EventRecordID>
      <Correlation />
      <Execution ProcessID="7680" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:13Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:08:26.0000000Z" />
      <EventRecordID>2652</EventRecordID>
      <Correlation />
      <Execution ProcessID="7680" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:22:53.0000000Z" />
      <EventRecordID>2651</EventRecordID>
      <Correlation />
      <Execution ProcessID="3024" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:41Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:32:24.0000000Z" />
      <EventRecordID>2650</EventRecordID>
      <Correlation />
      <Execution ProcessID="3024" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:18:44.0000000Z" />
      <EventRecordID>2649</EventRecordID>
      <Correlation />
      <Execution ProcessID="2476" ThreadID="3952" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">1645312067461807022</Data>
      <Data Name="BucketType">5</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER.2d7e1e6d-2fce-401e-9804-c682a637612d.tmp.WERInternalMetadata.xml</Data>
      <Data Name="StorePath">\\?\C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Critical_10.0.26100.3764__5e199f9f9d7e17f91d343fe6804ae56d4d4ab8dc_00000000_36b59f67-d40c-4838-91ed-3a6ba005f900</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">36b59f67-d40c-4838-91ed-3a6ba005f900</Data>
      <Data Name="ReportStatus">268435456</Data>
      <Data Name="HashedBucket">eff1b3c91036ad4dc6d5529badb97bae</Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:40:37.0000000Z" />
      <EventRecordID>2648</EventRecordID>
      <Correlation />
      <Execution ProcessID="4756" ThreadID="4420" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">
      </Data>
      <Data Name="BucketType">0</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
\\?\C:\Windows\Logs\CBS\CBS.log
\\?\C:\Windows\Logs\CBS\CbsPersist_20250427220601.cab
\\?\C:\Windows\Logs\CBS\CbsPersist_20250427211157.cab
\\?\C:\Windows\Logs\CBS\container.etl
\\?\C:\WINDOWS\servicing\Sessions\Sessions.xml
\\?\C:\WINDOWS\system32\LogFiles\Scm\SCM.EVM
\\?\C:\WINDOWS\Logs\Cbs\FilterList.log</Data>
      <Data Name="StorePath">NULL</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">36b59f67-d40c-4838-91ed-3a6ba005f900</Data>
      <Data Name="ReportStatus">262148</Data>
      <Data Name="HashedBucket">
      </Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Windows Error Reporting" Guid="{0ead09bd-2157-539a-8d6d-c87f95b64d70}" />
      <EventID>1001</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:05:46.0000000Z" />
      <EventRecordID>2647</EventRecordID>
      <Correlation />
      <Execution ProcessID="4488" ThreadID="1652" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Bucket">
      </Data>
      <Data Name="BucketType">0</Data>
      <Data Name="EventName">WindowsWcpOtherFailure3</Data>
      <Data Name="Response">Not available</Data>
      <Data Name="CabId">0</Data>
      <Data Name="P1">10.0.26100.3764:1</Data>
      <Data Name="P2">wcp\rtllib\win32lib\delta_library.cpp</Data>
      <Data Name="P3">Windows::Rtl::DeltaDecompressBuffer</Data>
      <Data Name="P4">428</Data>
      <Data Name="P5">c0070306</Data>
      <Data Name="P6">0xdbfdd37d</Data>
      <Data Name="P7">
      </Data>
      <Data Name="P8">
      </Data>
      <Data Name="P9">
      </Data>
      <Data Name="P10">
      </Data>
      <Data Name="AttachedFiles">
      </Data>
      <Data Name="StorePath">\\?\C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_10.0.26100.3764__5e199f9f9d7e17f91d343fe6804ae56d4d4ab8dc_00000000_36b59f67-d40c-4838-91ed-3a6ba005f900</Data>
      <Data Name="AnalysisSymbol">
      </Data>
      <Data Name="Rechecking">0</Data>
      <Data Name="ReportId">36b59f67-d40c-4838-91ed-3a6ba005f900</Data>
      <Data Name="ReportStatus">4</Data>
      <Data Name="HashedBucket">
      </Data>
      <Data Name="CabGuid">0</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:23:03.0000000Z" />
      <EventRecordID>2646</EventRecordID>
      <Correlation />
      <Execution ProcessID="5828" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:36Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1033</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:23:30.0000000Z" />
      <EventRecordID>2645</EventRecordID>
      <Correlation />
      <Execution ProcessID="5828" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>(Security-SPP-Reserved-EnableNotificationMode) </Data>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>aa708397-8618-42de-b120-a44190ef456d</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:25:02.0000000Z" />
      <EventRecordID>2644</EventRecordID>
      <Correlation />
      <Execution ProcessID="5828" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Security-SPP-Reserved-LicenseProperties</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:31:48.0000000Z" />
      <EventRecordID>2643</EventRecordID>
      <Correlation />
      <Execution ProcessID="5828" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>AAD-AddDeviceJoinUserToAdminGroup-Policy</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:43:57.0000000Z" />
      <EventRecordID>2642</EventRecordID>
      <Correlation />
      <Execution ProcessID="5828" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:19:23.0000000Z" />
      <EventRecordID>2641</EventRecordID>
      <Correlation />
      <Execution ProcessID="4476" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:00Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:35:34.0000000Z" />
      <EventRecordID>2640</EventRecordID>
      <Correlation />
      <Execution ProcessID="4476" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:46:51.0000000Z" />
      <EventRecordID>2639</EventRecordID>
      <Correlation />
      <Execution ProcessID="7784" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:12:27.0000000Z" />
      <EventRecordID>2638</EventRecordID>
      <Correlation />
      <Execution ProcessID="7784" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:53:43.0000000Z" />
      <EventRecordID>2637</EventRecordID>
      <Correlation />
      <Execution ProcessID="7784" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:35:54.0000000Z" />
      <EventRecordID>2636</EventRecordID>
      <Correlation />
      <Execution ProcessID="2112" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:16Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:34:49.0000000Z" />
      <EventRecordID>2635</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5967888 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:37:00.0000000Z" />
      <EventRecordID>2636</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:37:12.0000000Z" />
      <EventRecordID>2637</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>emma.johnson successfully logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:37:25.0000000Z" />
      <EventRecordID>2638</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:37:45.0000000Z" />
      <EventRecordID>2639</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:37:58.0000000Z" />
      <EventRecordID>2640</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:38:02.0000000Z" />
      <EventRecordID>2641</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>isabella.martins successfully logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:38:15.0000000Z" />
      <EventRecordID>2642</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:38:30.0000000Z" />
      <EventRecordID>2643</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:38:45.0000000Z" />
      <EventRecordID>2644</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.brown successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:39:01.0000000Z" />
      <EventRecordID>2645</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>liam.brown successfully logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:22:02.0000000Z" />
      <EventRecordID>2634</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:17:24.0000000Z" />
      <EventRecordID>2633</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:27:14.0000000Z" />
      <EventRecordID>2632</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:45:31.0000000Z" />
      <EventRecordID>2631</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:52:11.0000000Z" />
      <EventRecordID>2630</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:07:39.0000000Z" />
      <EventRecordID>2629</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:26:53.0000000Z" />
      <EventRecordID>2628</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:26:51.0000000Z" />
      <EventRecordID>2627</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:44:03.0000000Z" />
      <EventRecordID>2626</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:39:59.0000000Z" />
      <EventRecordID>2625</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:50:31.0000000Z" />
      <EventRecordID>2624</EventRecordID>
      <Correlation />
      <Execution ProcessID="2112" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:34:18.0000000Z" />
      <EventRecordID>2623</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:35:03.0000000Z" />
      <EventRecordID>2622</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:28:59.0000000Z" />
      <EventRecordID>2621</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:37:17.0000000Z" />
      <EventRecordID>2620</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:16:21.0000000Z" />
      <EventRecordID>2619</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:20:01.0000000Z" />
      <EventRecordID>2618</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:56:51.0000000Z" />
      <EventRecordID>2617</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:16:00.0000000Z" />
      <EventRecordID>2616</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:20:33.0000000Z" />
      <EventRecordID>2615</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:48:26.0000000Z" />
      <EventRecordID>2614</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:08:03.0000000Z" />
      <EventRecordID>2613</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:18:33.0000000Z" />
      <EventRecordID>2612</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:43:50.0000000Z" />
      <EventRecordID>2611</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:53:34.0000000Z" />
      <EventRecordID>2610</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:11:58.0000000Z" />
      <EventRecordID>2609</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:07:48.0000000Z" />
      <EventRecordID>2608</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:37:34.0000000Z" />
      <EventRecordID>2607</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:42:59.0000000Z" />
      <EventRecordID>2606</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:08:53.0000000Z" />
      <EventRecordID>2605</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:31:56.0000000Z" />
      <EventRecordID>2604</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:12:59.0000000Z" />
      <EventRecordID>2603</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:39:22.0000000Z" />
      <EventRecordID>2602</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:14:23.0000000Z" />
      <EventRecordID>2601</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:10:07.0000000Z" />
      <EventRecordID>2600</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:21:57.0000000Z" />
      <EventRecordID>2599</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:27:51.0000000Z" />
      <EventRecordID>2598</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:47:58.0000000Z" />
      <EventRecordID>2597</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:31:31.0000000Z" />
      <EventRecordID>2596</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:30:03.0000000Z" />
      <EventRecordID>2595</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:56:09.0000000Z" />
      <EventRecordID>2594</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:17:03.0000000Z" />
      <EventRecordID>2593</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:15:21.0000000Z" />
      <EventRecordID>2592</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:49:58.0000000Z" />
      <EventRecordID>2591</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:37:38.0000000Z" />
      <EventRecordID>2590</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:49:12.0000000Z" />
      <EventRecordID>2589</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:43:48.0000000Z" />
      <EventRecordID>2588</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:54:40.0000000Z" />
      <EventRecordID>2587</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:49:39.0000000Z" />
      <EventRecordID>2586</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:56:53.0000000Z" />
      <EventRecordID>2585</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:21:38.0000000Z" />
      <EventRecordID>2584</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:05:52.0000000Z" />
      <EventRecordID>2583</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:16:15.0000000Z" />
      <EventRecordID>2582</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:10:00.0000000Z" />
      <EventRecordID>2581</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:29:04.0000000Z" />
      <EventRecordID>2580</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:18:47.0000000Z" />
      <EventRecordID>2579</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:17:27.0000000Z" />
      <EventRecordID>2578</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:12:29.0000000Z" />
      <EventRecordID>2577</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:32:05.0000000Z" />
      <EventRecordID>2576</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:26:36.0000000Z" />
      <EventRecordID>2575</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:13:18.0000000Z" />
      <EventRecordID>2574</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:57:02.0000000Z" />
      <EventRecordID>2573</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:47:44.0000000Z" />
      <EventRecordID>2572</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:37:36.0000000Z" />
      <EventRecordID>2571</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:45:11.0000000Z" />
      <EventRecordID>2570</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:17:59.0000000Z" />
      <EventRecordID>2569</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:26:30.0000000Z" />
      <EventRecordID>2568</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:39:47.0000000Z" />
      <EventRecordID>2567</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:03:24.0000000Z" />
      <EventRecordID>2566</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:51:05.0000000Z" />
      <EventRecordID>2565</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:34:58.0000000Z" />
      <EventRecordID>2564</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:46:56.0000000Z" />
      <EventRecordID>2563</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:23:52.0000000Z" />
      <EventRecordID>2562</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:27:19.0000000Z" />
      <EventRecordID>2561</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:23:35.0000000Z" />
      <EventRecordID>2560</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:30:50.0000000Z" />
      <EventRecordID>2559</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:33:43.0000000Z" />
      <EventRecordID>2558</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:30:28.0000000Z" />
      <EventRecordID>2557</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:29:24.0000000Z" />
      <EventRecordID>2556</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:18:48.0000000Z" />
      <EventRecordID>2555</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:13:38.0000000Z" />
      <EventRecordID>2554</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:00:44.0000000Z" />
      <EventRecordID>2553</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:22:43.0000000Z" />
      <EventRecordID>2552</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:23:16.0000000Z" />
      <EventRecordID>2551</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:55:30.0000000Z" />
      <EventRecordID>2550</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:46:21.0000000Z" />
      <EventRecordID>2549</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:16:10.0000000Z" />
      <EventRecordID>2548</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:23:51.0000000Z" />
      <EventRecordID>2547</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:30:32.0000000Z" />
      <EventRecordID>2546</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:05:18.0000000Z" />
      <EventRecordID>2545</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:09:53.0000000Z" />
      <EventRecordID>2544</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:03:57.0000000Z" />
      <EventRecordID>2543</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:28:34.0000000Z" />
      <EventRecordID>2542</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:47:56.0000000Z" />
      <EventRecordID>2541</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:35:35.0000000Z" />
      <EventRecordID>2540</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:37:36.0000000Z" />
      <EventRecordID>2539</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:25:46.0000000Z" />
      <EventRecordID>2538</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:09:47.0000000Z" />
      <EventRecordID>2537</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:34:19.0000000Z" />
      <EventRecordID>2536</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:09:27.0000000Z" />
      <EventRecordID>2535</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:14:03.0000000Z" />
      <EventRecordID>2534</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:12:03.0000000Z" />
      <EventRecordID>2533</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:20:29.0000000Z" />
      <EventRecordID>2532</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:29:01.0000000Z" />
      <EventRecordID>2531</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:56:01.0000000Z" />
      <EventRecordID>2530</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:45:58.0000000Z" />
      <EventRecordID>2529</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:29:22.0000000Z" />
      <EventRecordID>2528</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:05:13.0000000Z" />
      <EventRecordID>2527</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:46:01.0000000Z" />
      <EventRecordID>2526</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:22:35.0000000Z" />
      <EventRecordID>2525</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:20:47.0000000Z" />
      <EventRecordID>2524</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:02:22.0000000Z" />
      <EventRecordID>2523</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:42:26.0000000Z" />
      <EventRecordID>2522</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:17:43.0000000Z" />
      <EventRecordID>2521</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:46:30.0000000Z" />
      <EventRecordID>2520</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:50:42.0000000Z" />
      <EventRecordID>2519</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:20:20.0000000Z" />
      <EventRecordID>2518</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:39:38.0000000Z" />
      <EventRecordID>2517</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:34:49.0000000Z" />
      <EventRecordID>2516</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:50:29.0000000Z" />
      <EventRecordID>2515</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:35:34.0000000Z" />
      <EventRecordID>2514</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:32:48.0000000Z" />
      <EventRecordID>2513</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:38:24.0000000Z" />
      <EventRecordID>2512</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:46:09.0000000Z" />
      <EventRecordID>2511</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:32:35.0000000Z" />
      <EventRecordID>2510</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:51:51.0000000Z" />
      <EventRecordID>2509</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:07:41.0000000Z" />
      <EventRecordID>2508</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:07:39.0000000Z" />
      <EventRecordID>2507</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:33:39.0000000Z" />
      <EventRecordID>2506</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:03:46.0000000Z" />
      <EventRecordID>2505</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:58:32.0000000Z" />
      <EventRecordID>2504</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:33:13.0000000Z" />
      <EventRecordID>2503</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:24:37.0000000Z" />
      <EventRecordID>2502</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:56:10.0000000Z" />
      <EventRecordID>2501</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:49:43.0000000Z" />
      <EventRecordID>2500</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:25:22.0000000Z" />
      <EventRecordID>2499</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:23:18.0000000Z" />
      <EventRecordID>2498</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:38:37.0000000Z" />
      <EventRecordID>2497</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:49:09.0000000Z" />
      <EventRecordID>2496</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:00:50.0000000Z" />
      <EventRecordID>2495</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:51:19.0000000Z" />
      <EventRecordID>2494</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:26:10.0000000Z" />
      <EventRecordID>2493</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:05:43.0000000Z" />
      <EventRecordID>2492</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:00:41.0000000Z" />
      <EventRecordID>2491</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:33:03.0000000Z" />
      <EventRecordID>2490</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:00:59.0000000Z" />
      <EventRecordID>2489</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:31:30.0000000Z" />
      <EventRecordID>2488</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:50:13.0000000Z" />
      <EventRecordID>2487</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:17:24.0000000Z" />
      <EventRecordID>2486</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:16:25.0000000Z" />
      <EventRecordID>2485</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:02:58.0000000Z" />
      <EventRecordID>2484</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:38:42.0000000Z" />
      <EventRecordID>2483</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:40:53.0000000Z" />
      <EventRecordID>2482</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:38:04.0000000Z" />
      <EventRecordID>2481</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:04:46.0000000Z" />
      <EventRecordID>2480</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:10:39.0000000Z" />
      <EventRecordID>2479</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:54:29.0000000Z" />
      <EventRecordID>2478</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:55:16.0000000Z" />
      <EventRecordID>2477</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:52:56.0000000Z" />
      <EventRecordID>2476</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:48:17.0000000Z" />
      <EventRecordID>2475</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:56:35.0000000Z" />
      <EventRecordID>2474</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:01:09.0000000Z" />
      <EventRecordID>2473</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:54:25.0000000Z" />
      <EventRecordID>2472</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:00:12.0000000Z" />
      <EventRecordID>2471</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:27:52.0000000Z" />
      <EventRecordID>2470</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:23:38.0000000Z" />
      <EventRecordID>2469</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:03:30.0000000Z" />
      <EventRecordID>2468</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:57:13.0000000Z" />
      <EventRecordID>2467</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:43:54.0000000Z" />
      <EventRecordID>2466</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:31:10.0000000Z" />
      <EventRecordID>2465</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:59:46.0000000Z" />
      <EventRecordID>2464</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:06:25.0000000Z" />
      <EventRecordID>2463</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:10:57.0000000Z" />
      <EventRecordID>2462</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:58:07.0000000Z" />
      <EventRecordID>2461</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:44:30.0000000Z" />
      <EventRecordID>2460</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:44:05.0000000Z" />
      <EventRecordID>2459</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:35:07.0000000Z" />
      <EventRecordID>2458</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:30:38.0000000Z" />
      <EventRecordID>2457</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:52:01.0000000Z" />
      <EventRecordID>2456</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:21:35.0000000Z" />
      <EventRecordID>2455</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:25:18.0000000Z" />
      <EventRecordID>2454</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:59:58.0000000Z" />
      <EventRecordID>2453</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:16:51.0000000Z" />
      <EventRecordID>2452</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:53:36.0000000Z" />
      <EventRecordID>2451</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:02:40.0000000Z" />
      <EventRecordID>2450</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:38:13.0000000Z" />
      <EventRecordID>2449</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:31:34.0000000Z" />
      <EventRecordID>2448</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:37:20.0000000Z" />
      <EventRecordID>2447</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:08:30.0000000Z" />
      <EventRecordID>2446</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:58:18.0000000Z" />
      <EventRecordID>2445</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:50:16.0000000Z" />
      <EventRecordID>2444</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:58:05.0000000Z" />
      <EventRecordID>2443</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:56:04.0000000Z" />
      <EventRecordID>2442</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:11:12.0000000Z" />
      <EventRecordID>2441</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:12:38.0000000Z" />
      <EventRecordID>2440</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:33:44.0000000Z" />
      <EventRecordID>2439</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:00:51.0000000Z" />
      <EventRecordID>2438</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:57:06.0000000Z" />
      <EventRecordID>2437</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:09:48.0000000Z" />
      <EventRecordID>2436</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:42:58.0000000Z" />
      <EventRecordID>2435</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:31:57.0000000Z" />
      <EventRecordID>2434</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:06:24.0000000Z" />
      <EventRecordID>2433</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:40:14.0000000Z" />
      <EventRecordID>2432</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:37:00.0000000Z" />
      <EventRecordID>2431</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:56:59.0000000Z" />
      <EventRecordID>2430</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:40:36.0000000Z" />
      <EventRecordID>2429</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:25:05.0000000Z" />
      <EventRecordID>2428</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:24:20.0000000Z" />
      <EventRecordID>2427</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:44:34.0000000Z" />
      <EventRecordID>2426</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:35:31.0000000Z" />
      <EventRecordID>2425</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:59:42.0000000Z" />
      <EventRecordID>2424</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:52:48.0000000Z" />
      <EventRecordID>2423</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:44:25.0000000Z" />
      <EventRecordID>2422</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:57:06.0000000Z" />
      <EventRecordID>2421</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:49:57.0000000Z" />
      <EventRecordID>2420</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:56:15.0000000Z" />
      <EventRecordID>2419</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:05:31.0000000Z" />
      <EventRecordID>2418</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:06:30.0000000Z" />
      <EventRecordID>2417</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:06:55.0000000Z" />
      <EventRecordID>2416</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:20:26.0000000Z" />
      <EventRecordID>2415</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:10:19.0000000Z" />
      <EventRecordID>2414</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:38:09.0000000Z" />
      <EventRecordID>2413</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:21:32.0000000Z" />
      <EventRecordID>2412</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:13:31.0000000Z" />
      <EventRecordID>2411</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:08:33.0000000Z" />
      <EventRecordID>2410</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:33:02.0000000Z" />
      <EventRecordID>2409</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:06:25.0000000Z" />
      <EventRecordID>2408</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:49:09.0000000Z" />
      <EventRecordID>2407</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:45:00.0000000Z" />
      <EventRecordID>2406</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:05:10.0000000Z" />
      <EventRecordID>2405</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:18:06.0000000Z" />
      <EventRecordID>2404</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:16:44.0000000Z" />
      <EventRecordID>2403</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:03:41.0000000Z" />
      <EventRecordID>2402</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:32:07.0000000Z" />
      <EventRecordID>2401</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:12:43.0000000Z" />
      <EventRecordID>2400</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:31:43.0000000Z" />
      <EventRecordID>2399</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:30:21.0000000Z" />
      <EventRecordID>2398</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:12:13.0000000Z" />
      <EventRecordID>2397</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:58:36.0000000Z" />
      <EventRecordID>2396</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:28:52.0000000Z" />
      <EventRecordID>2395</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:53:37.0000000Z" />
      <EventRecordID>2394</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:57:10.0000000Z" />
      <EventRecordID>2393</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:54:27.0000000Z" />
      <EventRecordID>2392</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:06:55.0000000Z" />
      <EventRecordID>2391</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:38:54.0000000Z" />
      <EventRecordID>2390</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:23:12.0000000Z" />
      <EventRecordID>2389</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:00:56.0000000Z" />
      <EventRecordID>2388</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:44:13.0000000Z" />
      <EventRecordID>2387</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:31:55.0000000Z" />
      <EventRecordID>2386</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:36:24.0000000Z" />
      <EventRecordID>2385</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:56:26.0000000Z" />
      <EventRecordID>2384</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:22:14.0000000Z" />
      <EventRecordID>2383</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:01:05.0000000Z" />
      <EventRecordID>2382</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:55:16.0000000Z" />
      <EventRecordID>2381</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:36:19.0000000Z" />
      <EventRecordID>2380</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:17:55.0000000Z" />
      <EventRecordID>2379</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:26:40.0000000Z" />
      <EventRecordID>2378</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:14:26.0000000Z" />
      <EventRecordID>2377</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:47:12.0000000Z" />
      <EventRecordID>2376</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:53:32.0000000Z" />
      <EventRecordID>2375</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:24:33.0000000Z" />
      <EventRecordID>2374</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:55:19.0000000Z" />
      <EventRecordID>2373</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:15:16.0000000Z" />
      <EventRecordID>2372</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:42:41.0000000Z" />
      <EventRecordID>2371</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:20:30.0000000Z" />
      <EventRecordID>2370</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:42:23.0000000Z" />
      <EventRecordID>2369</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:59:29.0000000Z" />
      <EventRecordID>2368</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:20:25.0000000Z" />
      <EventRecordID>2367</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:17:33.0000000Z" />
      <EventRecordID>2366</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:34:50.0000000Z" />
      <EventRecordID>2365</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:54:31.0000000Z" />
      <EventRecordID>2364</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:54:52.0000000Z" />
      <EventRecordID>2363</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:22:18.0000000Z" />
      <EventRecordID>2362</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:38:42.0000000Z" />
      <EventRecordID>2361</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:48:50.0000000Z" />
      <EventRecordID>2360</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:26:26.0000000Z" />
      <EventRecordID>2359</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:56:36.0000000Z" />
      <EventRecordID>2358</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:28:23.0000000Z" />
      <EventRecordID>2357</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:49:54.0000000Z" />
      <EventRecordID>2356</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:50:56.0000000Z" />
      <EventRecordID>2355</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:58:25.0000000Z" />
      <EventRecordID>2354</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:29:32.0000000Z" />
      <EventRecordID>2353</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:47:10.0000000Z" />
      <EventRecordID>2352</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:23:51.0000000Z" />
      <EventRecordID>2351</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:57:36.0000000Z" />
      <EventRecordID>2350</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:17:48.0000000Z" />
      <EventRecordID>2349</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:09:06.0000000Z" />
      <EventRecordID>2348</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:08:37.0000000Z" />
      <EventRecordID>2347</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:52:42.0000000Z" />
      <EventRecordID>2346</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:21:56.0000000Z" />
      <EventRecordID>2345</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:35:27.0000000Z" />
      <EventRecordID>2344</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:40:01.0000000Z" />
      <EventRecordID>2343</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:40:37.0000000Z" />
      <EventRecordID>2342</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:26:46.0000000Z" />
      <EventRecordID>2341</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:13:03.0000000Z" />
      <EventRecordID>2340</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:40:14.0000000Z" />
      <EventRecordID>2339</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:10:51.0000000Z" />
      <EventRecordID>2338</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:15:18.0000000Z" />
      <EventRecordID>2337</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:43:49.0000000Z" />
      <EventRecordID>2336</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:23:42.0000000Z" />
      <EventRecordID>2335</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:41:50.0000000Z" />
      <EventRecordID>2334</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:10:50.0000000Z" />
      <EventRecordID>2333</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:00:05.0000000Z" />
      <EventRecordID>2332</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:54:39.0000000Z" />
      <EventRecordID>2331</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:48:47.0000000Z" />
      <EventRecordID>2330</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:35:43.0000000Z" />
      <EventRecordID>2329</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:23:14.0000000Z" />
      <EventRecordID>2328</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:14:56.0000000Z" />
      <EventRecordID>2327</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:47:14.0000000Z" />
      <EventRecordID>2326</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:35:20.0000000Z" />
      <EventRecordID>2325</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:27:47.0000000Z" />
      <EventRecordID>2324</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:14:39.0000000Z" />
      <EventRecordID>2323</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:44:22.0000000Z" />
      <EventRecordID>2322</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:08:47.0000000Z" />
      <EventRecordID>2321</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:33:35.0000000Z" />
      <EventRecordID>2320</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:57:35.0000000Z" />
      <EventRecordID>2319</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:44:19.0000000Z" />
      <EventRecordID>2318</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:35:16.0000000Z" />
      <EventRecordID>2317</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:46:23.0000000Z" />
      <EventRecordID>2316</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:09:25.0000000Z" />
      <EventRecordID>2315</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:54:29.0000000Z" />
      <EventRecordID>2314</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:59:19.0000000Z" />
      <EventRecordID>2313</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:44:26.0000000Z" />
      <EventRecordID>2312</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:50:58.0000000Z" />
      <EventRecordID>2311</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:03:24.0000000Z" />
      <EventRecordID>2310</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:56:23.0000000Z" />
      <EventRecordID>2309</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:44:55.0000000Z" />
      <EventRecordID>2308</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:39:21.0000000Z" />
      <EventRecordID>2307</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:45:38.0000000Z" />
      <EventRecordID>2306</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:34:19.0000000Z" />
      <EventRecordID>2305</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:09:28.0000000Z" />
      <EventRecordID>2304</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:52:10.0000000Z" />
      <EventRecordID>2303</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:36:20.0000000Z" />
      <EventRecordID>2302</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:22:53.0000000Z" />
      <EventRecordID>2301</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:16:11.0000000Z" />
      <EventRecordID>2300</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:23:40.0000000Z" />
      <EventRecordID>2299</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:54:01.0000000Z" />
      <EventRecordID>2298</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:44:56.0000000Z" />
      <EventRecordID>2297</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:00:27.0000000Z" />
      <EventRecordID>2296</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:03:59.0000000Z" />
      <EventRecordID>2295</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:51:42.0000000Z" />
      <EventRecordID>2294</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:08:45.0000000Z" />
      <EventRecordID>2293</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:37:46.0000000Z" />
      <EventRecordID>2292</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:34:43.0000000Z" />
      <EventRecordID>2291</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:32:53.0000000Z" />
      <EventRecordID>2290</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:15:26.0000000Z" />
      <EventRecordID>2289</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:06:49.0000000Z" />
      <EventRecordID>2288</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:50:50.0000000Z" />
      <EventRecordID>2287</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:43:30.0000000Z" />
      <EventRecordID>2286</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:38:23.0000000Z" />
      <EventRecordID>2285</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:22:02.0000000Z" />
      <EventRecordID>2284</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:37:33.0000000Z" />
      <EventRecordID>2283</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:26:08.0000000Z" />
      <EventRecordID>2282</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:00:36.0000000Z" />
      <EventRecordID>2281</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:06:22.0000000Z" />
      <EventRecordID>2280</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:57:08.0000000Z" />
      <EventRecordID>2279</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:55:32.0000000Z" />
      <EventRecordID>2278</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:01:48.0000000Z" />
      <EventRecordID>2277</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:13:54.0000000Z" />
      <EventRecordID>2276</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:39:08.0000000Z" />
      <EventRecordID>2275</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:14:13.0000000Z" />
      <EventRecordID>2274</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:36:00.0000000Z" />
      <EventRecordID>2273</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:15:00.0000000Z" />
      <EventRecordID>2272</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:41:52.0000000Z" />
      <EventRecordID>2271</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:50:53.0000000Z" />
      <EventRecordID>2270</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:18:39.0000000Z" />
      <EventRecordID>2269</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:20:40.0000000Z" />
      <EventRecordID>2268</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:59:14.0000000Z" />
      <EventRecordID>2267</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:17:35.0000000Z" />
      <EventRecordID>2266</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:08:04.0000000Z" />
      <EventRecordID>2265</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:24:37.0000000Z" />
      <EventRecordID>2264</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:05:12.0000000Z" />
      <EventRecordID>2263</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:14:58.0000000Z" />
      <EventRecordID>2262</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:50:21.0000000Z" />
      <EventRecordID>2261</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:27:21.0000000Z" />
      <EventRecordID>2260</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:38:02.0000000Z" />
      <EventRecordID>2259</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:44:34.0000000Z" />
      <EventRecordID>2258</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:17:47.0000000Z" />
      <EventRecordID>2257</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:03:52.0000000Z" />
      <EventRecordID>2256</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:33:07.0000000Z" />
      <EventRecordID>2255</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:25:30.0000000Z" />
      <EventRecordID>2254</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:05:21.0000000Z" />
      <EventRecordID>2253</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:53:11.0000000Z" />
      <EventRecordID>2252</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:34:53.0000000Z" />
      <EventRecordID>2251</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:37:55.0000000Z" />
      <EventRecordID>2250</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:39:06.0000000Z" />
      <EventRecordID>2249</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:52:39.0000000Z" />
      <EventRecordID>2248</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:13:28.0000000Z" />
      <EventRecordID>2247</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:15:49.0000000Z" />
      <EventRecordID>2246</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:34:36.0000000Z" />
      <EventRecordID>2245</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:23:04.0000000Z" />
      <EventRecordID>2244</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:20:16.0000000Z" />
      <EventRecordID>2243</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:34:56.0000000Z" />
      <EventRecordID>2242</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:47:36.0000000Z" />
      <EventRecordID>2241</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:30:08.0000000Z" />
      <EventRecordID>2240</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:20:28.0000000Z" />
      <EventRecordID>2239</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:54:12.0000000Z" />
      <EventRecordID>2238</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:03:08.0000000Z" />
      <EventRecordID>2237</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:23:32.0000000Z" />
      <EventRecordID>2236</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:15:35.0000000Z" />
      <EventRecordID>2235</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:09:46.0000000Z" />
      <EventRecordID>2234</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>joe.goldberg successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:30:51.0000000Z" />
      <EventRecordID>2233</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:57:05.0000000Z" />
      <EventRecordID>2232</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:40:06.0000000Z" />
      <EventRecordID>2231</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:06:53.0000000Z" />
      <EventRecordID>2230</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:01:58.0000000Z" />
      <EventRecordID>2229</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:59:46.0000000Z" />
      <EventRecordID>2228</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:59:21.0000000Z" />
      <EventRecordID>2227</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:39:59.0000000Z" />
      <EventRecordID>2226</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:39:12.0000000Z" />
      <EventRecordID>2225</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:13:55.0000000Z" />
      <EventRecordID>2224</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:46:30.0000000Z" />
      <EventRecordID>2223</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:21:31.0000000Z" />
      <EventRecordID>2222</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:12:44.0000000Z" />
      <EventRecordID>2221</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:27:22.0000000Z" />
      <EventRecordID>2220</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:46:08.0000000Z" />
      <EventRecordID>2219</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:07:23.0000000Z" />
      <EventRecordID>2218</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:51:05.0000000Z" />
      <EventRecordID>2217</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:51:06.0000000Z" />
      <EventRecordID>2216</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:22:31.0000000Z" />
      <EventRecordID>2215</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:36:41.0000000Z" />
      <EventRecordID>2214</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:34:13.0000000Z" />
      <EventRecordID>2213</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:47:56.0000000Z" />
      <EventRecordID>2212</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:45:09.0000000Z" />
      <EventRecordID>2211</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:35:10.0000000Z" />
      <EventRecordID>2210</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:03:50.0000000Z" />
      <EventRecordID>2209</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:34:11.0000000Z" />
      <EventRecordID>2208</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:25:09.0000000Z" />
      <EventRecordID>2207</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:54:00.0000000Z" />
      <EventRecordID>2206</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:52:58.0000000Z" />
      <EventRecordID>2205</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:22:58.0000000Z" />
      <EventRecordID>2204</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:22:41.0000000Z" />
      <EventRecordID>2203</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:15:55.0000000Z" />
      <EventRecordID>2202</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:47:48.0000000Z" />
      <EventRecordID>2201</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:31:14.0000000Z" />
      <EventRecordID>2200</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:02:12.0000000Z" />
      <EventRecordID>2199</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:10:31.0000000Z" />
      <EventRecordID>2198</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:00:44.0000000Z" />
      <EventRecordID>2197</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:44:00.0000000Z" />
      <EventRecordID>2196</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:47:23.0000000Z" />
      <EventRecordID>2195</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:39:35.0000000Z" />
      <EventRecordID>2194</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:41:21.0000000Z" />
      <EventRecordID>2193</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:31:51.0000000Z" />
      <EventRecordID>2192</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:06:32.0000000Z" />
      <EventRecordID>2191</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:35:17.0000000Z" />
      <EventRecordID>2190</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:41:17.0000000Z" />
      <EventRecordID>2189</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:30:58.0000000Z" />
      <EventRecordID>2188</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:57:16.0000000Z" />
      <EventRecordID>2187</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:06:51.0000000Z" />
      <EventRecordID>2186</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:21:06.0000000Z" />
      <EventRecordID>2185</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:27:44.0000000Z" />
      <EventRecordID>2184</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:48:35.0000000Z" />
      <EventRecordID>2183</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:58:06.0000000Z" />
      <EventRecordID>2182</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:18:33.0000000Z" />
      <EventRecordID>2181</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:43:23.0000000Z" />
      <EventRecordID>2180</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:36:09.0000000Z" />
      <EventRecordID>2179</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:19:35.0000000Z" />
      <EventRecordID>2178</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:24:57.0000000Z" />
      <EventRecordID>2177</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:42:50.0000000Z" />
      <EventRecordID>2176</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:20:03.0000000Z" />
      <EventRecordID>2175</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:22:22.0000000Z" />
      <EventRecordID>2174</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:18:52.0000000Z" />
      <EventRecordID>2173</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:50:45.0000000Z" />
      <EventRecordID>2172</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:14:20.0000000Z" />
      <EventRecordID>2171</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:45:52.0000000Z" />
      <EventRecordID>2170</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:21:43.0000000Z" />
      <EventRecordID>2169</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:58:21.0000000Z" />
      <EventRecordID>2168</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:27:37.0000000Z" />
      <EventRecordID>2167</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:13:22.0000000Z" />
      <EventRecordID>2166</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:01:50.0000000Z" />
      <EventRecordID>2165</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:09:51.0000000Z" />
      <EventRecordID>2164</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:45:58.0000000Z" />
      <EventRecordID>2163</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:30:20.0000000Z" />
      <EventRecordID>2162</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:07:35.0000000Z" />
      <EventRecordID>2161</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:57:52.0000000Z" />
      <EventRecordID>2160</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:34:51.0000000Z" />
      <EventRecordID>2159</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:29:26.0000000Z" />
      <EventRecordID>2158</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:31:51.0000000Z" />
      <EventRecordID>2157</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:28:48.0000000Z" />
      <EventRecordID>2156</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:32:12.0000000Z" />
      <EventRecordID>2155</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:33:13.0000000Z" />
      <EventRecordID>2154</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:32:17.0000000Z" />
      <EventRecordID>2153</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:15:48.0000000Z" />
      <EventRecordID>2152</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:46:25.0000000Z" />
      <EventRecordID>2151</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:57:11.0000000Z" />
      <EventRecordID>2150</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:10:32.0000000Z" />
      <EventRecordID>2149</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:21:05.0000000Z" />
      <EventRecordID>2148</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:31:04.0000000Z" />
      <EventRecordID>2147</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:22:52.0000000Z" />
      <EventRecordID>2146</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:39:54.0000000Z" />
      <EventRecordID>2145</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:39:02.0000000Z" />
      <EventRecordID>2144</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:09:07.0000000Z" />
      <EventRecordID>2143</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:17:03.0000000Z" />
      <EventRecordID>2142</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:33:29.0000000Z" />
      <EventRecordID>2141</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:42:27.0000000Z" />
      <EventRecordID>2140</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:59:44.0000000Z" />
      <EventRecordID>2139</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:30:41.0000000Z" />
      <EventRecordID>2138</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:16:48.0000000Z" />
      <EventRecordID>2137</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:43:40.0000000Z" />
      <EventRecordID>2136</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:58:50.0000000Z" />
      <EventRecordID>2135</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:39:05.0000000Z" />
      <EventRecordID>2134</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:11:36.0000000Z" />
      <EventRecordID>2133</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:21:36.0000000Z" />
      <EventRecordID>2132</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:22:55.0000000Z" />
      <EventRecordID>2131</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:54:58.0000000Z" />
      <EventRecordID>2130</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:21:56.0000000Z" />
      <EventRecordID>2129</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:33:37.0000000Z" />
      <EventRecordID>2128</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:01:49.0000000Z" />
      <EventRecordID>2127</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:05:25.0000000Z" />
      <EventRecordID>2126</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:26:18.0000000Z" />
      <EventRecordID>2125</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:13:43.0000000Z" />
      <EventRecordID>2124</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:31:03.0000000Z" />
      <EventRecordID>2123</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:35:42.0000000Z" />
      <EventRecordID>2122</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:10:04.0000000Z" />
      <EventRecordID>2121</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:56:55.0000000Z" />
      <EventRecordID>2120</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:21:39.0000000Z" />
      <EventRecordID>2119</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:29:34.0000000Z" />
      <EventRecordID>2118</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:39:43.0000000Z" />
      <EventRecordID>2117</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:57:17.0000000Z" />
      <EventRecordID>2116</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:01:40.0000000Z" />
      <EventRecordID>2115</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:49:17.0000000Z" />
      <EventRecordID>2114</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:01:20.0000000Z" />
      <EventRecordID>2113</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:11:15.0000000Z" />
      <EventRecordID>2112</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:31:53.0000000Z" />
      <EventRecordID>2111</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:16:19.0000000Z" />
      <EventRecordID>2110</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:27:10.0000000Z" />
      <EventRecordID>2109</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:15:57.0000000Z" />
      <EventRecordID>2108</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:36:09.0000000Z" />
      <EventRecordID>2107</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:22:33.0000000Z" />
      <EventRecordID>2106</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:59:37.0000000Z" />
      <EventRecordID>2105</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:45:08.0000000Z" />
      <EventRecordID>2104</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:38:27.0000000Z" />
      <EventRecordID>2103</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:49:45.0000000Z" />
      <EventRecordID>2102</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:45:26.0000000Z" />
      <EventRecordID>2101</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:12:20.0000000Z" />
      <EventRecordID>2100</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:00:27.0000000Z" />
      <EventRecordID>2099</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:07:36.0000000Z" />
      <EventRecordID>2098</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:18:48.0000000Z" />
      <EventRecordID>2097</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:28:22.0000000Z" />
      <EventRecordID>2096</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:07:49.0000000Z" />
      <EventRecordID>2095</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:26:43.0000000Z" />
      <EventRecordID>2094</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:46:45.0000000Z" />
      <EventRecordID>2093</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:24:43.0000000Z" />
      <EventRecordID>2092</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:32:45.0000000Z" />
      <EventRecordID>2091</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:01:31.0000000Z" />
      <EventRecordID>2090</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:32:06.0000000Z" />
      <EventRecordID>2089</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:06:49.0000000Z" />
      <EventRecordID>2088</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:47:29.0000000Z" />
      <EventRecordID>2087</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:24:03.0000000Z" />
      <EventRecordID>2086</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:43:42.0000000Z" />
      <EventRecordID>2085</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:17:23.0000000Z" />
      <EventRecordID>2084</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:20:18.0000000Z" />
      <EventRecordID>2083</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:08:22.0000000Z" />
      <EventRecordID>2082</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:30:20.0000000Z" />
      <EventRecordID>2081</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:26:15.0000000Z" />
      <EventRecordID>2080</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:48:43.0000000Z" />
      <EventRecordID>2079</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:10:39.0000000Z" />
      <EventRecordID>2078</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:53:16.0000000Z" />
      <EventRecordID>2077</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:30:39.0000000Z" />
      <EventRecordID>2076</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:09:40.0000000Z" />
      <EventRecordID>2075</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:11:33.0000000Z" />
      <EventRecordID>2074</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:33:16.0000000Z" />
      <EventRecordID>2073</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:16:43.0000000Z" />
      <EventRecordID>2072</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:42:29.0000000Z" />
      <EventRecordID>2071</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:27:17.0000000Z" />
      <EventRecordID>2070</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:39:18.0000000Z" />
      <EventRecordID>2069</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:05:09.0000000Z" />
      <EventRecordID>2068</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:24:31.0000000Z" />
      <EventRecordID>2067</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:59:19.0000000Z" />
      <EventRecordID>2066</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:35:27.0000000Z" />
      <EventRecordID>2065</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:38:34.0000000Z" />
      <EventRecordID>2064</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:44:10.0000000Z" />
      <EventRecordID>2063</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:22:35.0000000Z" />
      <EventRecordID>2062</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:22:45.0000000Z" />
      <EventRecordID>2061</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:09:21.0000000Z" />
      <EventRecordID>2060</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:16:45.0000000Z" />
      <EventRecordID>2059</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:38:49.0000000Z" />
      <EventRecordID>2058</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:02:56.0000000Z" />
      <EventRecordID>2057</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:13:36.0000000Z" />
      <EventRecordID>2056</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:59:45.0000000Z" />
      <EventRecordID>2055</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:25:22.0000000Z" />
      <EventRecordID>2054</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:07:35.0000000Z" />
      <EventRecordID>2053</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:05:54.0000000Z" />
      <EventRecordID>2052</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:27:14.0000000Z" />
      <EventRecordID>2051</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:28:06.0000000Z" />
      <EventRecordID>2050</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:40:26.0000000Z" />
      <EventRecordID>2049</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:34:45.0000000Z" />
      <EventRecordID>2048</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:03:11.0000000Z" />
      <EventRecordID>2047</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:18:08.0000000Z" />
      <EventRecordID>2046</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:49:39.0000000Z" />
      <EventRecordID>2045</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:09:26.0000000Z" />
      <EventRecordID>2044</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:02:01.0000000Z" />
      <EventRecordID>2043</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:46:41.0000000Z" />
      <EventRecordID>2042</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:25:29.0000000Z" />
      <EventRecordID>2041</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:05:22.0000000Z" />
      <EventRecordID>2040</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:41:27.0000000Z" />
      <EventRecordID>2039</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:39:35.0000000Z" />
      <EventRecordID>2038</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:47:20.0000000Z" />
      <EventRecordID>2037</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:12:11.0000000Z" />
      <EventRecordID>2036</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:08:27.0000000Z" />
      <EventRecordID>2035</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:34:25.0000000Z" />
      <EventRecordID>2034</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:07:25.0000000Z" />
      <EventRecordID>2033</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:05:02.0000000Z" />
      <EventRecordID>2032</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:07:36.0000000Z" />
      <EventRecordID>2031</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:48:12.0000000Z" />
      <EventRecordID>2030</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:24:45.0000000Z" />
      <EventRecordID>2029</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:27:39.0000000Z" />
      <EventRecordID>2028</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:30:52.0000000Z" />
      <EventRecordID>2027</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:33:35.0000000Z" />
      <EventRecordID>2026</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:27:22.0000000Z" />
      <EventRecordID>2025</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:53:08.0000000Z" />
      <EventRecordID>2024</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:32:08.0000000Z" />
      <EventRecordID>2023</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:08:05.0000000Z" />
      <EventRecordID>2022</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:17:52.0000000Z" />
      <EventRecordID>2021</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:32:46.0000000Z" />
      <EventRecordID>2020</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:52:09.0000000Z" />
      <EventRecordID>2019</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:39:34.0000000Z" />
      <EventRecordID>2018</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:22:21.0000000Z" />
      <EventRecordID>2017</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:40:49.0000000Z" />
      <EventRecordID>2016</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:25:45.0000000Z" />
      <EventRecordID>2015</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:20:10.0000000Z" />
      <EventRecordID>2014</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:37:54.0000000Z" />
      <EventRecordID>2013</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:35:30.0000000Z" />
      <EventRecordID>2012</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:03:33.0000000Z" />
      <EventRecordID>2011</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:36:28.0000000Z" />
      <EventRecordID>2010</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:39:51.0000000Z" />
      <EventRecordID>2009</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:20:55.0000000Z" />
      <EventRecordID>2008</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:18:22.0000000Z" />
      <EventRecordID>2007</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:50:05.0000000Z" />
      <EventRecordID>2006</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:22:00.0000000Z" />
      <EventRecordID>2005</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:33:20.0000000Z" />
      <EventRecordID>2004</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:45:29.0000000Z" />
      <EventRecordID>2003</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:20:47.0000000Z" />
      <EventRecordID>2002</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:35:03.0000000Z" />
      <EventRecordID>2001</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:16:35.0000000Z" />
      <EventRecordID>2000</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:35:34.0000000Z" />
      <EventRecordID>1999</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:22:17.0000000Z" />
      <EventRecordID>1998</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:24:05.0000000Z" />
      <EventRecordID>1997</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:08:21.0000000Z" />
      <EventRecordID>1996</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:45:57.0000000Z" />
      <EventRecordID>1995</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:36:12.0000000Z" />
      <EventRecordID>1994</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:22:06.0000000Z" />
      <EventRecordID>1993</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:24:34.0000000Z" />
      <EventRecordID>1992</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:19:30.0000000Z" />
      <EventRecordID>1991</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:23:06.0000000Z" />
      <EventRecordID>1990</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:39:09.0000000Z" />
      <EventRecordID>1989</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:27:27.0000000Z" />
      <EventRecordID>1988</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:04:37.0000000Z" />
      <EventRecordID>1987</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:49:11.0000000Z" />
      <EventRecordID>1986</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:34:07.0000000Z" />
      <EventRecordID>1985</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:07:20.0000000Z" />
      <EventRecordID>1984</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:16:41.0000000Z" />
      <EventRecordID>1983</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:18:52.0000000Z" />
      <EventRecordID>1982</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:21:00.0000000Z" />
      <EventRecordID>1981</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:27:55.0000000Z" />
      <EventRecordID>1980</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:08:32.0000000Z" />
      <EventRecordID>1979</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:57:34.0000000Z" />
      <EventRecordID>1978</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:49:25.0000000Z" />
      <EventRecordID>1977</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:17:37.0000000Z" />
      <EventRecordID>1976</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:49:03.0000000Z" />
      <EventRecordID>1975</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:02:24.0000000Z" />
      <EventRecordID>1974</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:56:51.0000000Z" />
      <EventRecordID>1973</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:57:18.0000000Z" />
      <EventRecordID>1972</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:25:00.0000000Z" />
      <EventRecordID>1971</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:03:15.0000000Z" />
      <EventRecordID>1970</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:47:04.0000000Z" />
      <EventRecordID>1969</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:55:32.0000000Z" />
      <EventRecordID>1968</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:23:33.0000000Z" />
      <EventRecordID>1967</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:46:30.0000000Z" />
      <EventRecordID>1966</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:27:20.0000000Z" />
      <EventRecordID>1965</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:25:01.0000000Z" />
      <EventRecordID>1964</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:09:20.0000000Z" />
      <EventRecordID>1963</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:36:37.0000000Z" />
      <EventRecordID>1962</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:06:41.0000000Z" />
      <EventRecordID>1961</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:45:17.0000000Z" />
      <EventRecordID>1960</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:50:12.0000000Z" />
      <EventRecordID>1959</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:41:03.0000000Z" />
      <EventRecordID>1958</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:14:54.0000000Z" />
      <EventRecordID>1957</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:01:32.0000000Z" />
      <EventRecordID>1956</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:47:06.0000000Z" />
      <EventRecordID>1955</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:05:24.0000000Z" />
      <EventRecordID>1954</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:36:15.0000000Z" />
      <EventRecordID>1953</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:51:49.0000000Z" />
      <EventRecordID>1952</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:44:39.0000000Z" />
      <EventRecordID>1951</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:13:05.0000000Z" />
      <EventRecordID>1950</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:05:21.0000000Z" />
      <EventRecordID>1949</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:48:29.0000000Z" />
      <EventRecordID>1948</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:40:48.0000000Z" />
      <EventRecordID>1947</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:49:31.0000000Z" />
      <EventRecordID>1946</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:23:05.0000000Z" />
      <EventRecordID>1945</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:28:49.0000000Z" />
      <EventRecordID>1944</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:22:31.0000000Z" />
      <EventRecordID>1943</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:25:12.0000000Z" />
      <EventRecordID>1942</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:57:34.0000000Z" />
      <EventRecordID>1941</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:46:13.0000000Z" />
      <EventRecordID>1940</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:51:39.0000000Z" />
      <EventRecordID>1939</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:26:08.0000000Z" />
      <EventRecordID>1938</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:44:05.0000000Z" />
      <EventRecordID>1937</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:43:09.0000000Z" />
      <EventRecordID>1936</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:11:24.0000000Z" />
      <EventRecordID>1935</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:12:32.0000000Z" />
      <EventRecordID>1934</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:37:29.0000000Z" />
      <EventRecordID>1933</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:55:47.0000000Z" />
      <EventRecordID>1932</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:17:55.0000000Z" />
      <EventRecordID>1931</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:40:44.0000000Z" />
      <EventRecordID>1930</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:50:55.0000000Z" />
      <EventRecordID>1929</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:46:01.0000000Z" />
      <EventRecordID>1928</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:24:43.0000000Z" />
      <EventRecordID>1927</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:35:55.0000000Z" />
      <EventRecordID>1926</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:23:09.0000000Z" />
      <EventRecordID>1925</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:57:47.0000000Z" />
      <EventRecordID>1924</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:42:52.0000000Z" />
      <EventRecordID>1923</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:39:48.0000000Z" />
      <EventRecordID>1922</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:55:49.0000000Z" />
      <EventRecordID>1921</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:34:45.0000000Z" />
      <EventRecordID>1920</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:29:16.0000000Z" />
      <EventRecordID>1919</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:28:16.0000000Z" />
      <EventRecordID>1918</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:45:11.0000000Z" />
      <EventRecordID>1917</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:23:26.0000000Z" />
      <EventRecordID>1916</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:13:31.0000000Z" />
      <EventRecordID>1915</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:32:12.0000000Z" />
      <EventRecordID>1914</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:19:42.0000000Z" />
      <EventRecordID>1913</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:03:30.0000000Z" />
      <EventRecordID>1912</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:07:27.0000000Z" />
      <EventRecordID>1911</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:37:55.0000000Z" />
      <EventRecordID>1910</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:34:37.0000000Z" />
      <EventRecordID>1909</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:44:51.0000000Z" />
      <EventRecordID>1908</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:58:53.0000000Z" />
      <EventRecordID>1907</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:44:30.0000000Z" />
      <EventRecordID>1906</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:43:01.0000000Z" />
      <EventRecordID>1905</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:38:08.0000000Z" />
      <EventRecordID>1904</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:18:11.0000000Z" />
      <EventRecordID>1903</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:11:32.0000000Z" />
      <EventRecordID>1902</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:23:42.0000000Z" />
      <EventRecordID>1901</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:12:28.0000000Z" />
      <EventRecordID>1900</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:42:06.0000000Z" />
      <EventRecordID>1899</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:33:04.0000000Z" />
      <EventRecordID>1898</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:03:39.0000000Z" />
      <EventRecordID>1897</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:39:33.0000000Z" />
      <EventRecordID>1896</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:54:37.0000000Z" />
      <EventRecordID>1895</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:00:53.0000000Z" />
      <EventRecordID>1894</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:05:13.0000000Z" />
      <EventRecordID>1893</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:07:31.0000000Z" />
      <EventRecordID>1892</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:05:15.0000000Z" />
      <EventRecordID>1891</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:20:01.0000000Z" />
      <EventRecordID>1890</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:40:29.0000000Z" />
      <EventRecordID>1889</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:33:59.0000000Z" />
      <EventRecordID>1888</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:32:56.0000000Z" />
      <EventRecordID>1887</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:35:53.0000000Z" />
      <EventRecordID>1886</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:39:51.0000000Z" />
      <EventRecordID>1885</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:20:26.0000000Z" />
      <EventRecordID>1884</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:55:12.0000000Z" />
      <EventRecordID>1883</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:58:04.0000000Z" />
      <EventRecordID>1882</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:36:05.0000000Z" />
      <EventRecordID>1881</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:57:49.0000000Z" />
      <EventRecordID>1880</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:20:15.0000000Z" />
      <EventRecordID>1879</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:17:46.0000000Z" />
      <EventRecordID>1878</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:24:51.0000000Z" />
      <EventRecordID>1877</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:23:27.0000000Z" />
      <EventRecordID>1876</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:25:00.0000000Z" />
      <EventRecordID>1875</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:33:36.0000000Z" />
      <EventRecordID>1874</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:36:41.0000000Z" />
      <EventRecordID>1873</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:45:39.0000000Z" />
      <EventRecordID>1872</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:19:14.0000000Z" />
      <EventRecordID>1871</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:17:38.0000000Z" />
      <EventRecordID>1870</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:44:49.0000000Z" />
      <EventRecordID>1869</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:11:34.0000000Z" />
      <EventRecordID>1868</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:13:32.0000000Z" />
      <EventRecordID>1867</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:03:25.0000000Z" />
      <EventRecordID>1866</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:18:32.0000000Z" />
      <EventRecordID>1865</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:38:16.0000000Z" />
      <EventRecordID>1864</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:55:02.0000000Z" />
      <EventRecordID>1863</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:53:29.0000000Z" />
      <EventRecordID>1862</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:34:59.0000000Z" />
      <EventRecordID>1861</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:43:07.0000000Z" />
      <EventRecordID>1860</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:44:17.0000000Z" />
      <EventRecordID>1859</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:37:40.0000000Z" />
      <EventRecordID>1858</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:23:55.0000000Z" />
      <EventRecordID>1857</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:31:04.0000000Z" />
      <EventRecordID>1856</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:49:07.0000000Z" />
      <EventRecordID>1855</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:09:13.0000000Z" />
      <EventRecordID>1854</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:05:17.0000000Z" />
      <EventRecordID>1853</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:33:22.0000000Z" />
      <EventRecordID>1852</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:50:45.0000000Z" />
      <EventRecordID>1851</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:53:05.0000000Z" />
      <EventRecordID>1850</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:53:30.0000000Z" />
      <EventRecordID>1849</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:01:15.0000000Z" />
      <EventRecordID>1848</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:03:04.0000000Z" />
      <EventRecordID>1847</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:43:45.0000000Z" />
      <EventRecordID>1846</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:54:23.0000000Z" />
      <EventRecordID>1845</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:28:51.0000000Z" />
      <EventRecordID>1844</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:48:39.0000000Z" />
      <EventRecordID>1843</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:16:03.0000000Z" />
      <EventRecordID>1842</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:16:29.0000000Z" />
      <EventRecordID>1841</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:38:12.0000000Z" />
      <EventRecordID>1840</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:21:18.0000000Z" />
      <EventRecordID>1839</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:29:20.0000000Z" />
      <EventRecordID>1838</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:46:31.0000000Z" />
      <EventRecordID>1837</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:41:49.0000000Z" />
      <EventRecordID>1836</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:11:29.0000000Z" />
      <EventRecordID>1835</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:14:05.0000000Z" />
      <EventRecordID>1834</EventRecordID>
      <Correlation />
      <Execution ProcessID="5368" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.araf a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:11:03.0000000Z" />
      <EventRecordID>1833</EventRecordID>
      <Correlation />
      <Execution ProcessID="7384" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:38Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">15</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:50:04.0000000Z" />
      <EventRecordID>1832</EventRecordID>
      <Correlation />
      <Execution ProcessID="7784" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Windows Defender</Data>
      <Data>SECURITY_PRODUCT_STATE_ON</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="SecurityCenter" />
      <EventID Qualifiers="0">1</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:18:02.0000000Z" />
      <EventRecordID>1831</EventRecordID>
      <Correlation />
      <Execution ProcessID="7784" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:57:33.0000000Z" />
      <EventRecordID>1830</EventRecordID>
      <Correlation />
      <Execution ProcessID="7384" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">900</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:54:39.0000000Z" />
      <EventRecordID>1829</EventRecordID>
      <Correlation />
      <Execution ProcessID="7384" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>&lt;explicit&gt;</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="edgeupdate" />
      <EventID Qualifiers="0">0</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:38:58.0000000Z" />
      <EventRecordID>1828</EventRecordID>
      <Correlation />
      <Execution ProcessID="4572" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Service stopped</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">903</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:39:23.0000000Z" />
      <EventRecordID>1827</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:42:33.0000000Z" />
      <EventRecordID>1826</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-04-28T23:05:09Z</Data>
      <Data>TBL</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Search" Guid="{CA4E628D-8567-4896-AB6B-835B221F373F}" EventSourceName="Windows Search Service" />
      <EventID Qualifiers="16384">1003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:49:09.0000000Z" />
      <EventRecordID>1825</EventRecordID>
      <Correlation />
      <Execution ProcessID="7544" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data Name="ExtraInfo">
      </Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:49:27.0000000Z" />
      <EventRecordID>1824</EventRecordID>
      <Correlation />
      <Execution ProcessID="796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:16:07.0000000Z" />
      <EventRecordID>1823</EventRecordID>
      <Correlation />
      <Execution ProcessID="796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:08:27.0000000Z" />
      <EventRecordID>1822</EventRecordID>
      <Correlation />
      <Execution ProcessID="2808" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">EXE\PC01$</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(94ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:16:17.0000000Z" />
      <EventRecordID>1821</EventRecordID>
      <Correlation />
      <Execution ProcessID="2808" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">Local system</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(609ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-CertificateServicesClient-CertEnroll" Guid="{54164045-7C50-4905-963F-E5BC1EEF0CCA}" EventSourceName="CertEnroll" />
      <EventID Qualifiers="49754">86</EventID>
      <Version>0</Version>
      <Level>2</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:45:43.0000000Z" />
      <EventRecordID>1820</EventRecordID>
      <Correlation />
      <Execution ProcessID="2808" ThreadID="0" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
      <Data Name="Context">EXE\PC01$</Data>
      <Data Name="Url">https://-KeyId-ab296836f5553fa06530af2ccd5f1c75a3b2ff8e.microsoftaik.azure.net/templates/Aik/scep</Data>
      <Data Name="MessageText">GetCACaps
</Data>
      <Data Name="Method">GET(609ms)</Data>
      <Data Name="Stage">GetCACaps</Data>
      <Data Name="ErrorCode">The connection with the server was terminated abnormally 0x80072efe (WinHttp: 12030 ERROR_WINHTTP_CONNECTION_ERROR)</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>5617</EventID>
      <Version>2</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:34:48.0000000Z" />
      <EventRecordID>1819</EventRecordID>
      <Correlation />
      <Execution ProcessID="3228" ThreadID="2504" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">902</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:21:49.0000000Z" />
      <EventRecordID>1818</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>10.0.26100.1742</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="32768">1037</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:38:12.0000000Z" />
      <EventRecordID>1817</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>validity</Data>
      <Data>129351</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1003</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:24:31.0000000Z" />
      <EventRecordID>1816</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>
1: 399f0697-886b-4881-894c-4ff6c52e7d8f, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)(?)(?)])(1 )(2 )(3 )]
2: aa708397-8618-42de-b120-a44190ef456d, 1, 0 [(0 [0x00000000, 1, 0], [(?)( 1 0x00000000)(?)( 2 0x00000000 0 0 msft:rm/algorithm/hwid/4.0 0x00000000 0)(?)( 9 0x00000000 90 129351)( 10 0x00000000 msft:rm/algorithm/flags/1.0)(?)])(1 )(2 )(3 )]

</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1033</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:32:13.0000000Z" />
      <EventRecordID>1815</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>(Security-SPP-Reserved-EnableNotificationMode) </Data>
      <Data>55c92734-d682-4d71-983e-d6ec3f16059f</Data>
      <Data>aa708397-8618-42de-b120-a44190ef456d</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:01:53.0000000Z" />
      <EventRecordID>1814</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>Security-SPP-Reserved-LicenseProperties</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1034</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:27:41.0000000Z" />
      <EventRecordID>1813</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>AAD-AddDeviceJoinUserToAdminGroup-Policy</Data>
      <Data>100</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">1066</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:04:27.0000000Z" />
      <EventRecordID>1812</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>C:\WINDOWS\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/inherited/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:rm/algorithm/pkey/detect, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/ActionScheduler/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/statecollector/pkey, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\WINDOWS\system32\sppobjs.dll, msft:spp/volume/services/kms/activationinfo/1.0, 0x00000000, 0x00000000
</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:17:13.0000000Z" />
      <EventRecordID>1811</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-WMI" Guid="{1edeee53-0afe-4609-b846-d8c0b2075b1f}" />
      <EventID>5615</EventID>
      <Version>2</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:58:12.0000000Z" />
      <EventRecordID>1810</EventRecordID>
      <Correlation />
      <Execution ProcessID="3228" ThreadID="3460" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">900</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:47:45.0000000Z" />
      <EventRecordID>1809</EventRecordID>
      <Correlation />
      <Execution ProcessID="3532" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>TriggerStarted:6</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}" />
      <EventID>1531</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:01:56.0000000Z" />
      <EventRecordID>1808</EventRecordID>
      <Correlation />
      <Execution ProcessID="1820" ThreadID="2004" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}" />
      <EventID>1532</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8000000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:25:16.0000000Z" />
      <EventRecordID>1807</EventRecordID>
      <Correlation />
      <Execution ProcessID="2148" ThreadID="2240" />
      <Channel>Application</Channel>
            <Security UserID="S-1-5-18" />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name=".NET Runtime Optimization Service" />
      <EventID Qualifiers="0">1130</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:15:26.0000000Z" />
      <EventRecordID>1806</EventRecordID>
      <Correlation />
      <Execution ProcessID="1972" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>.NET Runtime Optimization Service (4.0.30319.0) - Installed from repository: mscorlib</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name=".NET Runtime Optimization Service" />
      <EventID Qualifiers="0">1130</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:37:34.0000000Z" />
      <EventRecordID>1805</EventRecordID>
      <Correlation />
      <Execution ProcessID="496" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>.NET Runtime Optimization Service (4.0.30319.0) - Installed from repository: mscorlib</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:57:25.0000000Z" />
      <EventRecordID>1804</EventRecordID>
      <Correlation />
      <Execution ProcessID="816" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>SessionEnv</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" EventSourceName="Wlclntfy" />
      <EventID Qualifiers="32768">6000</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:46:48.0000000Z" />
      <EventRecordID>1803</EventRecordID>
      <Correlation />
      <Execution ProcessID="816" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>WSearch</Data>
      <Binary>D9060000</Binary>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:19:53.0000000Z" />
      <EventRecordID>1802</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:14:40.0000000Z" />
      <EventRecordID>1801</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:28:12.0000000Z" />
      <EventRecordID>1800</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:10:00.0000000Z" />
      <EventRecordID>1799</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:48:57.0000000Z" />
      <EventRecordID>1798</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:11:30.0000000Z" />
      <EventRecordID>1797</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:44:29.0000000Z" />
      <EventRecordID>1796</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:05:59.0000000Z" />
      <EventRecordID>1795</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:19:20.0000000Z" />
      <EventRecordID>1794</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:58:03.0000000Z" />
      <EventRecordID>1793</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:19:33.0000000Z" />
      <EventRecordID>1792</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:39:33.0000000Z" />
      <EventRecordID>1791</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:15:42.0000000Z" />
      <EventRecordID>1790</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:38:44.0000000Z" />
      <EventRecordID>1789</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:41:19.0000000Z" />
      <EventRecordID>1788</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:13:16.0000000Z" />
      <EventRecordID>1787</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:10:47.0000000Z" />
      <EventRecordID>1786</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:47:01.0000000Z" />
      <EventRecordID>1785</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:25:33.0000000Z" />
      <EventRecordID>1784</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:51:25.0000000Z" />
      <EventRecordID>1783</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:06:48.0000000Z" />
      <EventRecordID>1782</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:59:36.0000000Z" />
      <EventRecordID>1781</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:47:49.0000000Z" />
      <EventRecordID>1780</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:52:43.0000000Z" />
      <EventRecordID>1779</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:46:23.0000000Z" />
      <EventRecordID>1778</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:55:00.0000000Z" />
      <EventRecordID>1777</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:29:39.0000000Z" />
      <EventRecordID>1776</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:34:21.0000000Z" />
      <EventRecordID>1775</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:12:01.0000000Z" />
      <EventRecordID>1774</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:41:56.0000000Z" />
      <EventRecordID>1773</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:45:21.0000000Z" />
      <EventRecordID>1772</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:56:18.0000000Z" />
      <EventRecordID>1771</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:32:03.0000000Z" />
      <EventRecordID>1770</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:48:20.0000000Z" />
      <EventRecordID>1769</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:59:41.0000000Z" />
      <EventRecordID>1768</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:32:32.0000000Z" />
      <EventRecordID>1767</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:10:09.0000000Z" />
      <EventRecordID>1766</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:37:19.0000000Z" />
      <EventRecordID>1765</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:23:23.0000000Z" />
      <EventRecordID>1764</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:04:37.0000000Z" />
      <EventRecordID>1763</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:17:25.0000000Z" />
      <EventRecordID>1762</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:44:54.0000000Z" />
      <EventRecordID>1761</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:32:34.0000000Z" />
      <EventRecordID>1760</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:22:37.0000000Z" />
      <EventRecordID>1759</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:31:43.0000000Z" />
      <EventRecordID>1758</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:30:22.0000000Z" />
      <EventRecordID>1757</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:49:33.0000000Z" />
      <EventRecordID>1756</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:04:04.0000000Z" />
      <EventRecordID>1755</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:33:19.0000000Z" />
      <EventRecordID>1754</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:21:33.0000000Z" />
      <EventRecordID>1753</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:55:09.0000000Z" />
      <EventRecordID>1752</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:35:51.0000000Z" />
      <EventRecordID>1751</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:37:46.0000000Z" />
      <EventRecordID>1750</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:31:16.0000000Z" />
      <EventRecordID>1749</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:13:30.0000000Z" />
      <EventRecordID>1748</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:34:32.0000000Z" />
      <EventRecordID>1747</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:56:18.0000000Z" />
      <EventRecordID>1746</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:18:18.0000000Z" />
      <EventRecordID>1745</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:25:11.0000000Z" />
      <EventRecordID>1744</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:54:50.0000000Z" />
      <EventRecordID>1743</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:43:45.0000000Z" />
      <EventRecordID>1742</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:46:47.0000000Z" />
      <EventRecordID>1741</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:02:13.0000000Z" />
      <EventRecordID>1740</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:51:18.0000000Z" />
      <EventRecordID>1739</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:01:33.0000000Z" />
      <EventRecordID>1738</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:32:50.0000000Z" />
      <EventRecordID>1737</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:59:16.0000000Z" />
      <EventRecordID>1736</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:38:30.0000000Z" />
      <EventRecordID>1735</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:04:27.0000000Z" />
      <EventRecordID>1734</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:37:22.0000000Z" />
      <EventRecordID>1733</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:09:00.0000000Z" />
      <EventRecordID>1732</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:41:03.0000000Z" />
      <EventRecordID>1731</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:08:16.0000000Z" />
      <EventRecordID>1730</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:48:36.0000000Z" />
      <EventRecordID>1729</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:09:14.0000000Z" />
      <EventRecordID>1728</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:10:14.0000000Z" />
      <EventRecordID>1727</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:20:54.0000000Z" />
      <EventRecordID>1726</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:27:59.0000000Z" />
      <EventRecordID>1725</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:39:18.0000000Z" />
      <EventRecordID>1724</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:00:19.0000000Z" />
      <EventRecordID>1723</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:55:57.0000000Z" />
      <EventRecordID>1722</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:05:00.0000000Z" />
      <EventRecordID>1721</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:34:23.0000000Z" />
      <EventRecordID>1720</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:08:44.0000000Z" />
      <EventRecordID>1719</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:21:50.0000000Z" />
      <EventRecordID>1718</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:49:05.0000000Z" />
      <EventRecordID>1717</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:46:21.0000000Z" />
      <EventRecordID>1716</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:56:41.0000000Z" />
      <EventRecordID>1715</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:51:39.0000000Z" />
      <EventRecordID>1714</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:20:27.0000000Z" />
      <EventRecordID>1713</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:54:49.0000000Z" />
      <EventRecordID>1712</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:51:04.0000000Z" />
      <EventRecordID>1711</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:35:43.0000000Z" />
      <EventRecordID>1710</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:08:44.0000000Z" />
      <EventRecordID>1709</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:45:21.0000000Z" />
      <EventRecordID>1708</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:13:45.0000000Z" />
      <EventRecordID>1707</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:59:13.0000000Z" />
      <EventRecordID>1706</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:16:50.0000000Z" />
      <EventRecordID>1705</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:07:24.0000000Z" />
      <EventRecordID>1704</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:45:46.0000000Z" />
      <EventRecordID>1703</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:21:37.0000000Z" />
      <EventRecordID>1702</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:37:25.0000000Z" />
      <EventRecordID>1701</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:21:00.0000000Z" />
      <EventRecordID>1700</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:01:48.0000000Z" />
      <EventRecordID>1699</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:43:58.0000000Z" />
      <EventRecordID>1698</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:43:57.0000000Z" />
      <EventRecordID>1697</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:29:59.0000000Z" />
      <EventRecordID>1696</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:36:52.0000000Z" />
      <EventRecordID>1695</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:28:07.0000000Z" />
      <EventRecordID>1694</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:58:27.0000000Z" />
      <EventRecordID>1693</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:53:45.0000000Z" />
      <EventRecordID>1692</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:17:08.0000000Z" />
      <EventRecordID>1691</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>gabinho.arfa a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:21:24.0000000Z" />
      <EventRecordID>1690</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:23:27.0000000Z" />
      <EventRecordID>1689</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:15:12.0000000Z" />
      <EventRecordID>1688</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:08:23.0000000Z" />
      <EventRecordID>1687</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:11:44.0000000Z" />
      <EventRecordID>1686</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:55:36.0000000Z" />
      <EventRecordID>1685</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:26:15.0000000Z" />
      <EventRecordID>1684</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:29:24.0000000Z" />
      <EventRecordID>1683</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:19:47.0000000Z" />
      <EventRecordID>1682</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:05:01.0000000Z" />
      <EventRecordID>1681</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:54:49.0000000Z" />
      <EventRecordID>1680</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:21:43.0000000Z" />
      <EventRecordID>1679</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:58:22.0000000Z" />
      <EventRecordID>1678</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:33:13.0000000Z" />
      <EventRecordID>1677</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:04:52.0000000Z" />
      <EventRecordID>1676</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:57:09.0000000Z" />
      <EventRecordID>1675</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:24:23.0000000Z" />
      <EventRecordID>1674</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:27:10.0000000Z" />
      <EventRecordID>1673</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:13:41.0000000Z" />
      <EventRecordID>1672</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:42:20.0000000Z" />
      <EventRecordID>1671</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:52:17.0000000Z" />
      <EventRecordID>1670</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:54:56.0000000Z" />
      <EventRecordID>1669</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:28:15.0000000Z" />
      <EventRecordID>1668</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:16:56.0000000Z" />
      <EventRecordID>1667</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:23:07.0000000Z" />
      <EventRecordID>1666</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:14:07.0000000Z" />
      <EventRecordID>1665</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:35:21.0000000Z" />
      <EventRecordID>1664</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:43:08.0000000Z" />
      <EventRecordID>1663</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:28:34.0000000Z" />
      <EventRecordID>1662</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:22:59.0000000Z" />
      <EventRecordID>1661</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:39:13.0000000Z" />
      <EventRecordID>1660</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:03:59.0000000Z" />
      <EventRecordID>1659</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:16:04.0000000Z" />
      <EventRecordID>1658</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:35:23.0000000Z" />
      <EventRecordID>1657</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:31:46.0000000Z" />
      <EventRecordID>1656</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:34:32.0000000Z" />
      <EventRecordID>1655</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:29:45.0000000Z" />
      <EventRecordID>1654</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:47:13.0000000Z" />
      <EventRecordID>1653</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:21:42.0000000Z" />
      <EventRecordID>1652</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:08:46.0000000Z" />
      <EventRecordID>1651</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:22:04.0000000Z" />
      <EventRecordID>1650</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:46:53.0000000Z" />
      <EventRecordID>1649</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:40:57.0000000Z" />
      <EventRecordID>1648</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:37:36.0000000Z" />
      <EventRecordID>1647</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:56:24.0000000Z" />
      <EventRecordID>1646</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:20:39.0000000Z" />
      <EventRecordID>1645</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:23:03.0000000Z" />
      <EventRecordID>1644</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:52:50.0000000Z" />
      <EventRecordID>1643</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:34:15.0000000Z" />
      <EventRecordID>1642</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:19:28.0000000Z" />
      <EventRecordID>1641</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:48:24.0000000Z" />
      <EventRecordID>1640</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:09:43.0000000Z" />
      <EventRecordID>1639</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:13:08.0000000Z" />
      <EventRecordID>1638</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:49:02.0000000Z" />
      <EventRecordID>1637</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:53:10.0000000Z" />
      <EventRecordID>1636</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:38:16.0000000Z" />
      <EventRecordID>1635</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:41:57.0000000Z" />
      <EventRecordID>1634</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:27:56.0000000Z" />
      <EventRecordID>1633</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:35:04.0000000Z" />
      <EventRecordID>1632</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:16:27.0000000Z" />
      <EventRecordID>1631</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:34:27.0000000Z" />
      <EventRecordID>1630</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:28:45.0000000Z" />
      <EventRecordID>1629</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:08:21.0000000Z" />
      <EventRecordID>1628</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:51:24.0000000Z" />
      <EventRecordID>1627</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:44:26.0000000Z" />
      <EventRecordID>1626</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:45:23.0000000Z" />
      <EventRecordID>1625</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:58:57.0000000Z" />
      <EventRecordID>1624</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:37:53.0000000Z" />
      <EventRecordID>1623</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:50:11.0000000Z" />
      <EventRecordID>1622</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:28:31.0000000Z" />
      <EventRecordID>1621</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:31:21.0000000Z" />
      <EventRecordID>1620</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:39:59.0000000Z" />
      <EventRecordID>1619</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:00:39.0000000Z" />
      <EventRecordID>1618</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:22:05.0000000Z" />
      <EventRecordID>1617</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:21:26.0000000Z" />
      <EventRecordID>1616</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:27:35.0000000Z" />
      <EventRecordID>1615</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:59:20.0000000Z" />
      <EventRecordID>1614</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:33:00.0000000Z" />
      <EventRecordID>1613</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:46:08.0000000Z" />
      <EventRecordID>1612</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:12:53.0000000Z" />
      <EventRecordID>1611</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:16:54.0000000Z" />
      <EventRecordID>1610</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:50:28.0000000Z" />
      <EventRecordID>1609</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:11:57.0000000Z" />
      <EventRecordID>1608</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:35:33.0000000Z" />
      <EventRecordID>1607</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:05:42.0000000Z" />
      <EventRecordID>1606</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:55:14.0000000Z" />
      <EventRecordID>1605</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:16:28.0000000Z" />
      <EventRecordID>1604</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:56:52.0000000Z" />
      <EventRecordID>1603</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:43:43.0000000Z" />
      <EventRecordID>1602</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:00:07.0000000Z" />
      <EventRecordID>1601</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:43:34.0000000Z" />
      <EventRecordID>1600</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:35:56.0000000Z" />
      <EventRecordID>1599</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:04:21.0000000Z" />
      <EventRecordID>1598</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:11:37.0000000Z" />
      <EventRecordID>1597</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:36:12.0000000Z" />
      <EventRecordID>1596</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:59:28.0000000Z" />
      <EventRecordID>1595</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:17:45.0000000Z" />
      <EventRecordID>1594</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:00:14.0000000Z" />
      <EventRecordID>1593</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:22:03.0000000Z" />
      <EventRecordID>1592</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:43:03.0000000Z" />
      <EventRecordID>1591</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:25:20.0000000Z" />
      <EventRecordID>1590</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:44:57.0000000Z" />
      <EventRecordID>1589</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:22:21.0000000Z" />
      <EventRecordID>1588</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:45:08.0000000Z" />
      <EventRecordID>1587</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:27:57.0000000Z" />
      <EventRecordID>1586</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:32:03.0000000Z" />
      <EventRecordID>1585</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:48:39.0000000Z" />
      <EventRecordID>1584</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:50:05.0000000Z" />
      <EventRecordID>1583</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:08:10.0000000Z" />
      <EventRecordID>1582</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:59:46.0000000Z" />
      <EventRecordID>1581</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:15:27.0000000Z" />
      <EventRecordID>1580</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:25:54.0000000Z" />
      <EventRecordID>1579</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:28:14.0000000Z" />
      <EventRecordID>1578</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:33:30.0000000Z" />
      <EventRecordID>1577</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:35:23.0000000Z" />
      <EventRecordID>1576</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:19:40.0000000Z" />
      <EventRecordID>1575</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:14:40.0000000Z" />
      <EventRecordID>1574</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:49:56.0000000Z" />
      <EventRecordID>1573</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:04:10.0000000Z" />
      <EventRecordID>1572</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:24:59.0000000Z" />
      <EventRecordID>1571</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:50:03.0000000Z" />
      <EventRecordID>1570</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:19:07.0000000Z" />
      <EventRecordID>1569</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:08:29.0000000Z" />
      <EventRecordID>1568</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:57:03.0000000Z" />
      <EventRecordID>1567</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:18:35.0000000Z" />
      <EventRecordID>1566</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:12:47.0000000Z" />
      <EventRecordID>1565</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:02:56.0000000Z" />
      <EventRecordID>1564</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:44:19.0000000Z" />
      <EventRecordID>1563</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:03:19.0000000Z" />
      <EventRecordID>1562</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:51:22.0000000Z" />
      <EventRecordID>1561</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:41:43.0000000Z" />
      <EventRecordID>1560</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:31:51.0000000Z" />
      <EventRecordID>1559</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:13:46.0000000Z" />
      <EventRecordID>1558</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:51:16.0000000Z" />
      <EventRecordID>1557</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:16:49.0000000Z" />
      <EventRecordID>1556</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:26:36.0000000Z" />
      <EventRecordID>1555</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:27:57.0000000Z" />
      <EventRecordID>1554</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:29:10.0000000Z" />
      <EventRecordID>1553</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:21:23.0000000Z" />
      <EventRecordID>1552</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:25:33.0000000Z" />
      <EventRecordID>1551</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:26:08.0000000Z" />
      <EventRecordID>1550</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:13:43.0000000Z" />
      <EventRecordID>1549</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:21:24.0000000Z" />
      <EventRecordID>1548</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:37:25.0000000Z" />
      <EventRecordID>1547</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:44:47.0000000Z" />
      <EventRecordID>1546</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:21:20.0000000Z" />
      <EventRecordID>1545</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:29:48.0000000Z" />
      <EventRecordID>1544</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:27:48.0000000Z" />
      <EventRecordID>1543</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:51:32.0000000Z" />
      <EventRecordID>1542</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:30:08.0000000Z" />
      <EventRecordID>1541</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:03:03.0000000Z" />
      <EventRecordID>1540</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:20:20.0000000Z" />
      <EventRecordID>1539</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:16:31.0000000Z" />
      <EventRecordID>1538</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:43:48.0000000Z" />
      <EventRecordID>1537</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:39:55.0000000Z" />
      <EventRecordID>1536</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:16:12.0000000Z" />
      <EventRecordID>1535</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:46:14.0000000Z" />
      <EventRecordID>1534</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:51:26.0000000Z" />
      <EventRecordID>1533</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:46:29.0000000Z" />
      <EventRecordID>1532</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:06:27.0000000Z" />
      <EventRecordID>1531</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:48:32.0000000Z" />
      <EventRecordID>1530</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:23:30.0000000Z" />
      <EventRecordID>1529</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:13:39.0000000Z" />
      <EventRecordID>1528</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:19:31.0000000Z" />
      <EventRecordID>1527</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:41:32.0000000Z" />
      <EventRecordID>1526</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:14:12.0000000Z" />
      <EventRecordID>1525</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:40:25.0000000Z" />
      <EventRecordID>1524</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:54:56.0000000Z" />
      <EventRecordID>1523</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:58:22.0000000Z" />
      <EventRecordID>1522</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:42:05.0000000Z" />
      <EventRecordID>1521</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:48:33.0000000Z" />
      <EventRecordID>1520</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:30:00.0000000Z" />
      <EventRecordID>1519</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:18:52.0000000Z" />
      <EventRecordID>1518</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:14:59.0000000Z" />
      <EventRecordID>1517</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:33:49.0000000Z" />
      <EventRecordID>1516</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:50:27.0000000Z" />
      <EventRecordID>1515</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:17:59.0000000Z" />
      <EventRecordID>1514</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:14:49.0000000Z" />
      <EventRecordID>1513</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:30:34.0000000Z" />
      <EventRecordID>1512</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:15:56.0000000Z" />
      <EventRecordID>1511</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:40:18.0000000Z" />
      <EventRecordID>1510</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:00:09.0000000Z" />
      <EventRecordID>1509</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:47:07.0000000Z" />
      <EventRecordID>1508</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:44:27.0000000Z" />
      <EventRecordID>1507</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:54:02.0000000Z" />
      <EventRecordID>1506</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:15:17.0000000Z" />
      <EventRecordID>1505</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:31:53.0000000Z" />
      <EventRecordID>1504</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:51:49.0000000Z" />
      <EventRecordID>1503</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:02:48.0000000Z" />
      <EventRecordID>1502</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:13:19.0000000Z" />
      <EventRecordID>1501</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:58:09.0000000Z" />
      <EventRecordID>1500</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:31:32.0000000Z" />
      <EventRecordID>1499</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:35:36.0000000Z" />
      <EventRecordID>1498</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:40:20.0000000Z" />
      <EventRecordID>1497</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:18:22.0000000Z" />
      <EventRecordID>1496</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:33:23.0000000Z" />
      <EventRecordID>1495</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:25:33.0000000Z" />
      <EventRecordID>1494</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:08:57.0000000Z" />
      <EventRecordID>1493</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:43:37.0000000Z" />
      <EventRecordID>1492</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:43:00.0000000Z" />
      <EventRecordID>1491</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:09:25.0000000Z" />
      <EventRecordID>1490</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T11:35:07.0000000Z" />
      <EventRecordID>1489</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:23:27.0000000Z" />
      <EventRecordID>1488</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:38:30.0000000Z" />
      <EventRecordID>1487</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:00:43.0000000Z" />
      <EventRecordID>1486</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:31:14.0000000Z" />
      <EventRecordID>1485</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:42:25.0000000Z" />
      <EventRecordID>1484</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:24:32.0000000Z" />
      <EventRecordID>1483</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:27:16.0000000Z" />
      <EventRecordID>1482</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:00:23.0000000Z" />
      <EventRecordID>1481</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:54:10.0000000Z" />
      <EventRecordID>1480</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:27:39.0000000Z" />
      <EventRecordID>1479</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:44:52.0000000Z" />
      <EventRecordID>1478</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:16:13.0000000Z" />
      <EventRecordID>1477</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:46:00.0000000Z" />
      <EventRecordID>1476</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:36:24.0000000Z" />
      <EventRecordID>1475</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:22:27.0000000Z" />
      <EventRecordID>1474</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:55:33.0000000Z" />
      <EventRecordID>1473</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:16:23.0000000Z" />
      <EventRecordID>1472</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:55:36.0000000Z" />
      <EventRecordID>1471</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:39:00.0000000Z" />
      <EventRecordID>1470</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:50:43.0000000Z" />
      <EventRecordID>1469</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:49:34.0000000Z" />
      <EventRecordID>1468</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:30:20.0000000Z" />
      <EventRecordID>1467</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:26:18.0000000Z" />
      <EventRecordID>1466</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:16:34.0000000Z" />
      <EventRecordID>1465</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:28:46.0000000Z" />
      <EventRecordID>1464</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:46:10.0000000Z" />
      <EventRecordID>1463</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:12:41.0000000Z" />
      <EventRecordID>1462</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:30:41.0000000Z" />
      <EventRecordID>1461</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:43:34.0000000Z" />
      <EventRecordID>1460</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:38:01.0000000Z" />
      <EventRecordID>1459</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:25:35.0000000Z" />
      <EventRecordID>1458</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:54:34.0000000Z" />
      <EventRecordID>1457</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:25:38.0000000Z" />
      <EventRecordID>1456</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:34:28.0000000Z" />
      <EventRecordID>1455</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:24:37.0000000Z" />
      <EventRecordID>1454</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:17:47.0000000Z" />
      <EventRecordID>1453</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:34:54.0000000Z" />
      <EventRecordID>1452</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:30:51.0000000Z" />
      <EventRecordID>1451</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:59:34.0000000Z" />
      <EventRecordID>1450</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:30:52.0000000Z" />
      <EventRecordID>1449</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:52:02.0000000Z" />
      <EventRecordID>1448</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:52:05.0000000Z" />
      <EventRecordID>1447</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:24:12.0000000Z" />
      <EventRecordID>1446</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:00:16.0000000Z" />
      <EventRecordID>1445</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:48:28.0000000Z" />
      <EventRecordID>1444</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:55:47.0000000Z" />
      <EventRecordID>1443</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:18:57.0000000Z" />
      <EventRecordID>1442</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:59:12.0000000Z" />
      <EventRecordID>1441</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:10:16.0000000Z" />
      <EventRecordID>1440</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:39:19.0000000Z" />
      <EventRecordID>1439</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:37:09.0000000Z" />
      <EventRecordID>1438</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:11:49.0000000Z" />
      <EventRecordID>1437</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:06:34.0000000Z" />
      <EventRecordID>1436</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:32:56.0000000Z" />
      <EventRecordID>1435</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:17:24.0000000Z" />
      <EventRecordID>1434</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:31:32.0000000Z" />
      <EventRecordID>1433</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:00:33.0000000Z" />
      <EventRecordID>1432</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:50:03.0000000Z" />
      <EventRecordID>1431</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:06:51.0000000Z" />
      <EventRecordID>1430</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:00:57.0000000Z" />
      <EventRecordID>1429</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:53:29.0000000Z" />
      <EventRecordID>1428</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:49:02.0000000Z" />
      <EventRecordID>1427</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:20:42.0000000Z" />
      <EventRecordID>1426</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:18:40.0000000Z" />
      <EventRecordID>1425</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:21:23.0000000Z" />
      <EventRecordID>1424</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:00:31.0000000Z" />
      <EventRecordID>1423</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:48:43.0000000Z" />
      <EventRecordID>1422</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:10:23.0000000Z" />
      <EventRecordID>1421</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:20:38.0000000Z" />
      <EventRecordID>1420</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:25:33.0000000Z" />
      <EventRecordID>1419</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:19:51.0000000Z" />
      <EventRecordID>1418</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:47:35.0000000Z" />
      <EventRecordID>1417</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:09:30.0000000Z" />
      <EventRecordID>1416</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:14:01.0000000Z" />
      <EventRecordID>1415</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:26:42.0000000Z" />
      <EventRecordID>1414</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:45:54.0000000Z" />
      <EventRecordID>1413</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:26:40.0000000Z" />
      <EventRecordID>1412</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:53:47.0000000Z" />
      <EventRecordID>1411</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:48:00.0000000Z" />
      <EventRecordID>1410</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:00:25.0000000Z" />
      <EventRecordID>1409</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:24:40.0000000Z" />
      <EventRecordID>1408</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:56:05.0000000Z" />
      <EventRecordID>1407</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:29:09.0000000Z" />
      <EventRecordID>1406</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:19:25.0000000Z" />
      <EventRecordID>1405</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:45:07.0000000Z" />
      <EventRecordID>1404</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:13:38.0000000Z" />
      <EventRecordID>1403</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:51:32.0000000Z" />
      <EventRecordID>1402</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:51:56.0000000Z" />
      <EventRecordID>1401</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:41:54.0000000Z" />
      <EventRecordID>1400</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:19:32.0000000Z" />
      <EventRecordID>1399</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:26:42.0000000Z" />
      <EventRecordID>1398</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:50:06.0000000Z" />
      <EventRecordID>1397</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:22:57.0000000Z" />
      <EventRecordID>1396</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:02:45.0000000Z" />
      <EventRecordID>1395</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:44:50.0000000Z" />
      <EventRecordID>1394</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:48:30.0000000Z" />
      <EventRecordID>1393</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:24:16.0000000Z" />
      <EventRecordID>1392</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:19:04.0000000Z" />
      <EventRecordID>1391</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:22:37.0000000Z" />
      <EventRecordID>1390</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:34:21.0000000Z" />
      <EventRecordID>1389</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:16:16.0000000Z" />
      <EventRecordID>1388</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:28:02.0000000Z" />
      <EventRecordID>1387</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:15:24.0000000Z" />
      <EventRecordID>1386</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:17:54.0000000Z" />
      <EventRecordID>1385</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:26:16.0000000Z" />
      <EventRecordID>1384</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:22:07.0000000Z" />
      <EventRecordID>1383</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:46:25.0000000Z" />
      <EventRecordID>1382</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:13:36.0000000Z" />
      <EventRecordID>1381</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:51:45.0000000Z" />
      <EventRecordID>1380</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:21:18.0000000Z" />
      <EventRecordID>1379</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:23:04.0000000Z" />
      <EventRecordID>1378</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:06:41.0000000Z" />
      <EventRecordID>1377</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:34:25.0000000Z" />
      <EventRecordID>1376</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:20:29.0000000Z" />
      <EventRecordID>1375</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:20:33.0000000Z" />
      <EventRecordID>1374</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:41:21.0000000Z" />
      <EventRecordID>1373</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:41:10.0000000Z" />
      <EventRecordID>1372</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:55:16.0000000Z" />
      <EventRecordID>1371</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:23:12.0000000Z" />
      <EventRecordID>1370</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:34:14.0000000Z" />
      <EventRecordID>1369</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:53:53.0000000Z" />
      <EventRecordID>1368</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:51:46.0000000Z" />
      <EventRecordID>1367</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:15:14.0000000Z" />
      <EventRecordID>1366</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:34:05.0000000Z" />
      <EventRecordID>1365</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:12:37.0000000Z" />
      <EventRecordID>1364</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:07:03.0000000Z" />
      <EventRecordID>1363</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:15:10.0000000Z" />
      <EventRecordID>1362</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:18:09.0000000Z" />
      <EventRecordID>1361</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:21:48.0000000Z" />
      <EventRecordID>1360</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:33:19.0000000Z" />
      <EventRecordID>1359</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:26:53.0000000Z" />
      <EventRecordID>1358</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:40:19.0000000Z" />
      <EventRecordID>1357</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:45:29.0000000Z" />
      <EventRecordID>1356</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:18:30.0000000Z" />
      <EventRecordID>1355</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:17:04.0000000Z" />
      <EventRecordID>1354</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:11:13.0000000Z" />
      <EventRecordID>1353</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:57:20.0000000Z" />
      <EventRecordID>1352</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:22:02.0000000Z" />
      <EventRecordID>1351</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:52:12.0000000Z" />
      <EventRecordID>1350</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:44:41.0000000Z" />
      <EventRecordID>1349</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:44:38.0000000Z" />
      <EventRecordID>1348</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:00:28.0000000Z" />
      <EventRecordID>1347</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:43:18.0000000Z" />
      <EventRecordID>1346</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:21:48.0000000Z" />
      <EventRecordID>1345</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:56:04.0000000Z" />
      <EventRecordID>1344</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:20:14.0000000Z" />
      <EventRecordID>1343</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:52:50.0000000Z" />
      <EventRecordID>1342</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:47:00.0000000Z" />
      <EventRecordID>1341</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:39:08.0000000Z" />
      <EventRecordID>1340</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:40:19.0000000Z" />
      <EventRecordID>1339</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:57:15.0000000Z" />
      <EventRecordID>1338</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:59:48.0000000Z" />
      <EventRecordID>1337</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:14:52.0000000Z" />
      <EventRecordID>1336</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:51:39.0000000Z" />
      <EventRecordID>1335</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:50:30.0000000Z" />
      <EventRecordID>1334</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:54:09.0000000Z" />
      <EventRecordID>1333</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:26:05.0000000Z" />
      <EventRecordID>1332</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:24:43.0000000Z" />
      <EventRecordID>1331</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:06:46.0000000Z" />
      <EventRecordID>1330</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:51:19.0000000Z" />
      <EventRecordID>1329</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:12:44.0000000Z" />
      <EventRecordID>1328</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:36:24.0000000Z" />
      <EventRecordID>1327</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:40:17.0000000Z" />
      <EventRecordID>1326</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:28:44.0000000Z" />
      <EventRecordID>1325</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:00:44.0000000Z" />
      <EventRecordID>1324</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:58:41.0000000Z" />
      <EventRecordID>1323</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:55:29.0000000Z" />
      <EventRecordID>1322</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:40:14.0000000Z" />
      <EventRecordID>1321</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:15:02.0000000Z" />
      <EventRecordID>1320</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:33:00.0000000Z" />
      <EventRecordID>1319</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:05:13.0000000Z" />
      <EventRecordID>1318</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:27:24.0000000Z" />
      <EventRecordID>1317</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:46:39.0000000Z" />
      <EventRecordID>1316</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:58:38.0000000Z" />
      <EventRecordID>1315</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:26:28.0000000Z" />
      <EventRecordID>1314</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:26:11.0000000Z" />
      <EventRecordID>1313</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:55:39.0000000Z" />
      <EventRecordID>1312</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:36:10.0000000Z" />
      <EventRecordID>1311</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:47:07.0000000Z" />
      <EventRecordID>1310</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:40:38.0000000Z" />
      <EventRecordID>1309</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:09:04.0000000Z" />
      <EventRecordID>1308</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:26:54.0000000Z" />
      <EventRecordID>1307</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:26:22.0000000Z" />
      <EventRecordID>1306</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:34:25.0000000Z" />
      <EventRecordID>1305</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:21:55.0000000Z" />
      <EventRecordID>1304</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:33:28.0000000Z" />
      <EventRecordID>1303</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:21:21.0000000Z" />
      <EventRecordID>1302</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:38:14.0000000Z" />
      <EventRecordID>1301</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:30:25.0000000Z" />
      <EventRecordID>1300</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:59:57.0000000Z" />
      <EventRecordID>1299</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:42:22.0000000Z" />
      <EventRecordID>1298</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:39:34.0000000Z" />
      <EventRecordID>1297</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:34:36.0000000Z" />
      <EventRecordID>1296</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:13:40.0000000Z" />
      <EventRecordID>1295</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:42:16.0000000Z" />
      <EventRecordID>1294</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:38:50.0000000Z" />
      <EventRecordID>1293</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:18:50.0000000Z" />
      <EventRecordID>1292</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:29:36.0000000Z" />
      <EventRecordID>1291</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:43:30.0000000Z" />
      <EventRecordID>1290</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>john.doe a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:37:40.0000000Z" />
      <EventRecordID>1289</EventRecordID>
      <Correlation />
      <Execution ProcessID="2060" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:32Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:59:00.0000000Z" />
      <EventRecordID>1288</EventRecordID>
      <Correlation />
      <Execution ProcessID="2060" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="16384">16384</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:45:41.0000000Z" />
      <EventRecordID>1287</EventRecordID>
      <Correlation />
      <Execution ProcessID="7404" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>2025-06-26T18:56:10Z</Data>
      <Data>RulesEngine</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-SPP" Guid="{E23B33B0-C8C9-472C-A5F9-F2BDFEA0F156}" EventSourceName="Software Protection Platform Service" />
      <EventID Qualifiers="49152">16394</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>0</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:01:28.0000000Z" />
      <EventRecordID>1286</EventRecordID>
      <Correlation />
      <Execution ProcessID="7404" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:26:35.0000000Z" />
      <EventRecordID>1285</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:52:08.0000000Z" />
      <EventRecordID>1284</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:59:05.0000000Z" />
      <EventRecordID>1283</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:09:28.0000000Z" />
      <EventRecordID>1282</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:35:12.0000000Z" />
      <EventRecordID>1281</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:39:27.0000000Z" />
      <EventRecordID>1280</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:00:17.0000000Z" />
      <EventRecordID>1279</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:28:28.0000000Z" />
      <EventRecordID>1278</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:59:20.0000000Z" />
      <EventRecordID>1277</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:41:24.0000000Z" />
      <EventRecordID>1276</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:40:56.0000000Z" />
      <EventRecordID>1275</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:35:40.0000000Z" />
      <EventRecordID>1274</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T17:24:09.0000000Z" />
      <EventRecordID>1273</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:19:53.0000000Z" />
      <EventRecordID>1272</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:59:02.0000000Z" />
      <EventRecordID>1271</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:02:12.0000000Z" />
      <EventRecordID>1270</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:26:17.0000000Z" />
      <EventRecordID>1269</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:06:56.0000000Z" />
      <EventRecordID>1268</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:16:11.0000000Z" />
      <EventRecordID>1267</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:45:01.0000000Z" />
      <EventRecordID>1266</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:10:43.0000000Z" />
      <EventRecordID>1265</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:35:25.0000000Z" />
      <EventRecordID>1264</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:29:08.0000000Z" />
      <EventRecordID>1263</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:21:25.0000000Z" />
      <EventRecordID>1262</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:45:59.0000000Z" />
      <EventRecordID>1261</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:41:33.0000000Z" />
      <EventRecordID>1260</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:28:08.0000000Z" />
      <EventRecordID>1259</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:19:54.0000000Z" />
      <EventRecordID>1258</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:08:50.0000000Z" />
      <EventRecordID>1257</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:30:10.0000000Z" />
      <EventRecordID>1256</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:07:45.0000000Z" />
      <EventRecordID>1255</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:23:51.0000000Z" />
      <EventRecordID>1254</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:42:10.0000000Z" />
      <EventRecordID>1253</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:35:07.0000000Z" />
      <EventRecordID>1252</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:14:05.0000000Z" />
      <EventRecordID>1251</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:04:25.0000000Z" />
      <EventRecordID>1250</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:19:13.0000000Z" />
      <EventRecordID>1249</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:19:22.0000000Z" />
      <EventRecordID>1248</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:46:57.0000000Z" />
      <EventRecordID>1247</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:06:27.0000000Z" />
      <EventRecordID>1246</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:29:29.0000000Z" />
      <EventRecordID>1245</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:15:27.0000000Z" />
      <EventRecordID>1244</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:46:08.0000000Z" />
      <EventRecordID>1243</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:00:28.0000000Z" />
      <EventRecordID>1242</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:09:02.0000000Z" />
      <EventRecordID>1241</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:19:32.0000000Z" />
      <EventRecordID>1240</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:28:38.0000000Z" />
      <EventRecordID>1239</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:53:36.0000000Z" />
      <EventRecordID>1238</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:11:21.0000000Z" />
      <EventRecordID>1237</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:43:07.0000000Z" />
      <EventRecordID>1236</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:32:04.0000000Z" />
      <EventRecordID>1235</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:00:11.0000000Z" />
      <EventRecordID>1234</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:00:08.0000000Z" />
      <EventRecordID>1233</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:37:56.0000000Z" />
      <EventRecordID>1232</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:55:41.0000000Z" />
      <EventRecordID>1231</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:17:18.0000000Z" />
      <EventRecordID>1230</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:52:21.0000000Z" />
      <EventRecordID>1229</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:57:34.0000000Z" />
      <EventRecordID>1228</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:55:34.0000000Z" />
      <EventRecordID>1227</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:50:50.0000000Z" />
      <EventRecordID>1226</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:20:42.0000000Z" />
      <EventRecordID>1225</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:06:55.0000000Z" />
      <EventRecordID>1224</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:44:49.0000000Z" />
      <EventRecordID>1223</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:28:42.0000000Z" />
      <EventRecordID>1222</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:52:29.0000000Z" />
      <EventRecordID>1221</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:24:59.0000000Z" />
      <EventRecordID>1220</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:14:17.0000000Z" />
      <EventRecordID>1219</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:08:00.0000000Z" />
      <EventRecordID>1218</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:22:49.0000000Z" />
      <EventRecordID>1217</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:35:52.0000000Z" />
      <EventRecordID>1216</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:09:57.0000000Z" />
      <EventRecordID>1215</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:40:40.0000000Z" />
      <EventRecordID>1214</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:38:46.0000000Z" />
      <EventRecordID>1213</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:35:13.0000000Z" />
      <EventRecordID>1212</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:11:08.0000000Z" />
      <EventRecordID>1211</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:29:30.0000000Z" />
      <EventRecordID>1210</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:13:41.0000000Z" />
      <EventRecordID>1209</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:26:13.0000000Z" />
      <EventRecordID>1208</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:00:12.0000000Z" />
      <EventRecordID>1207</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:00:18.0000000Z" />
      <EventRecordID>1206</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:43:59.0000000Z" />
      <EventRecordID>1205</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:27:46.0000000Z" />
      <EventRecordID>1204</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:09:27.0000000Z" />
      <EventRecordID>1203</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:42:14.0000000Z" />
      <EventRecordID>1202</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:32:24.0000000Z" />
      <EventRecordID>1201</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:53:23.0000000Z" />
      <EventRecordID>1200</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:55:51.0000000Z" />
      <EventRecordID>1199</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:29:13.0000000Z" />
      <EventRecordID>1198</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:12:26.0000000Z" />
      <EventRecordID>1197</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:42:45.0000000Z" />
      <EventRecordID>1196</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:44:23.0000000Z" />
      <EventRecordID>1195</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:22:28.0000000Z" />
      <EventRecordID>1194</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:32:31.0000000Z" />
      <EventRecordID>1193</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:19:30.0000000Z" />
      <EventRecordID>1192</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:57:46.0000000Z" />
      <EventRecordID>1191</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:24:46.0000000Z" />
      <EventRecordID>1190</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:02:26.0000000Z" />
      <EventRecordID>1189</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:18:35.0000000Z" />
      <EventRecordID>1188</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:45:21.0000000Z" />
      <EventRecordID>1187</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:23:46.0000000Z" />
      <EventRecordID>1186</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:02:26.0000000Z" />
      <EventRecordID>1185</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:40:54.0000000Z" />
      <EventRecordID>1184</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:57:56.0000000Z" />
      <EventRecordID>1183</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:47:19.0000000Z" />
      <EventRecordID>1182</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:11:05.0000000Z" />
      <EventRecordID>1181</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:43:13.0000000Z" />
      <EventRecordID>1180</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:59:30.0000000Z" />
      <EventRecordID>1179</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:08:12.0000000Z" />
      <EventRecordID>1178</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:56:55.0000000Z" />
      <EventRecordID>1177</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:19:48.0000000Z" />
      <EventRecordID>1176</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:58:16.0000000Z" />
      <EventRecordID>1175</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:47:30.0000000Z" />
      <EventRecordID>1174</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:35:55.0000000Z" />
      <EventRecordID>1173</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:30:10.0000000Z" />
      <EventRecordID>1172</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:56:03.0000000Z" />
      <EventRecordID>1171</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:18:05.0000000Z" />
      <EventRecordID>1170</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:16:20.0000000Z" />
      <EventRecordID>1169</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:08:36.0000000Z" />
      <EventRecordID>1168</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:15:39.0000000Z" />
      <EventRecordID>1167</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:24:05.0000000Z" />
      <EventRecordID>1166</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T08:59:28.0000000Z" />
      <EventRecordID>1165</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:52:51.0000000Z" />
      <EventRecordID>1164</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:26:22.0000000Z" />
      <EventRecordID>1163</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:13:06.0000000Z" />
      <EventRecordID>1162</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:14:56.0000000Z" />
      <EventRecordID>1161</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:17:57.0000000Z" />
      <EventRecordID>1160</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:53:41.0000000Z" />
      <EventRecordID>1159</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:00:37.0000000Z" />
      <EventRecordID>1158</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:44:04.0000000Z" />
      <EventRecordID>1157</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:54:40.0000000Z" />
      <EventRecordID>1156</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:43:39.0000000Z" />
      <EventRecordID>1155</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:37:03.0000000Z" />
      <EventRecordID>1154</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:40:17.0000000Z" />
      <EventRecordID>1153</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:13:48.0000000Z" />
      <EventRecordID>1152</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:01:28.0000000Z" />
      <EventRecordID>1151</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:08:59.0000000Z" />
      <EventRecordID>1150</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:42:54.0000000Z" />
      <EventRecordID>1149</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:29:58.0000000Z" />
      <EventRecordID>1148</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:35:29.0000000Z" />
      <EventRecordID>1147</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:06:04.0000000Z" />
      <EventRecordID>1146</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:07:43.0000000Z" />
      <EventRecordID>1145</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:18:08.0000000Z" />
      <EventRecordID>1144</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:49:03.0000000Z" />
      <EventRecordID>1143</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:12:16.0000000Z" />
      <EventRecordID>1142</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:03:08.0000000Z" />
      <EventRecordID>1141</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:04:55.0000000Z" />
      <EventRecordID>1140</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:15:59.0000000Z" />
      <EventRecordID>1139</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:55:17.0000000Z" />
      <EventRecordID>1138</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T16:59:02.0000000Z" />
      <EventRecordID>1137</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:03:38.0000000Z" />
      <EventRecordID>1136</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:56:40.0000000Z" />
      <EventRecordID>1135</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:35:26.0000000Z" />
      <EventRecordID>1134</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:47:56.0000000Z" />
      <EventRecordID>1133</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:46:17.0000000Z" />
      <EventRecordID>1132</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:52:42.0000000Z" />
      <EventRecordID>1131</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:57:43.0000000Z" />
      <EventRecordID>1130</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:06:50.0000000Z" />
      <EventRecordID>1129</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:43:48.0000000Z" />
      <EventRecordID>1128</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:43:39.0000000Z" />
      <EventRecordID>1127</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:52:00.0000000Z" />
      <EventRecordID>1126</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:16:29.0000000Z" />
      <EventRecordID>1125</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:32:43.0000000Z" />
      <EventRecordID>1124</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:47:28.0000000Z" />
      <EventRecordID>1123</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:31:33.0000000Z" />
      <EventRecordID>1122</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:37:07.0000000Z" />
      <EventRecordID>1121</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:15:41.0000000Z" />
      <EventRecordID>1120</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:16:12.0000000Z" />
      <EventRecordID>1119</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:04:44.0000000Z" />
      <EventRecordID>1118</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:35:15.0000000Z" />
      <EventRecordID>1117</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:56:25.0000000Z" />
      <EventRecordID>1116</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:28:29.0000000Z" />
      <EventRecordID>1115</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:22:05.0000000Z" />
      <EventRecordID>1114</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:38:57.0000000Z" />
      <EventRecordID>1113</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:29:26.0000000Z" />
      <EventRecordID>1112</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:55:24.0000000Z" />
      <EventRecordID>1111</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:52:55.0000000Z" />
      <EventRecordID>1110</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:46:53.0000000Z" />
      <EventRecordID>1109</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:54:53.0000000Z" />
      <EventRecordID>1108</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:51:05.0000000Z" />
      <EventRecordID>1107</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:53:50.0000000Z" />
      <EventRecordID>1106</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:17:46.0000000Z" />
      <EventRecordID>1105</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:35:43.0000000Z" />
      <EventRecordID>1104</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:23:10.0000000Z" />
      <EventRecordID>1103</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:11:27.0000000Z" />
      <EventRecordID>1102</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:01:22.0000000Z" />
      <EventRecordID>1101</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:11:05.0000000Z" />
      <EventRecordID>1100</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:21:46.0000000Z" />
      <EventRecordID>1099</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:10:13.0000000Z" />
      <EventRecordID>1098</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:34:07.0000000Z" />
      <EventRecordID>1097</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:51:27.0000000Z" />
      <EventRecordID>1096</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:07:35.0000000Z" />
      <EventRecordID>1095</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:08:28.0000000Z" />
      <EventRecordID>1094</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:09:26.0000000Z" />
      <EventRecordID>1093</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:57:01.0000000Z" />
      <EventRecordID>1092</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:03:04.0000000Z" />
      <EventRecordID>1091</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:12:31.0000000Z" />
      <EventRecordID>1090</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T16:56:33.0000000Z" />
      <EventRecordID>1089</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:04:26.0000000Z" />
      <EventRecordID>1088</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:15:01.0000000Z" />
      <EventRecordID>1087</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:27:00.0000000Z" />
      <EventRecordID>1086</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:04:52.0000000Z" />
      <EventRecordID>1085</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:50:30.0000000Z" />
      <EventRecordID>1084</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:56:31.0000000Z" />
      <EventRecordID>1083</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:14:22.0000000Z" />
      <EventRecordID>1082</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:53:45.0000000Z" />
      <EventRecordID>1081</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T15:46:14.0000000Z" />
      <EventRecordID>1080</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T10:47:57.0000000Z" />
      <EventRecordID>1079</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:53:42.0000000Z" />
      <EventRecordID>1078</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:57:10.0000000Z" />
      <EventRecordID>1077</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:02:12.0000000Z" />
      <EventRecordID>1076</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T12:58:47.0000000Z" />
      <EventRecordID>1075</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:29:03.0000000Z" />
      <EventRecordID>1074</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:51:05.0000000Z" />
      <EventRecordID>1073</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:26:14.0000000Z" />
      <EventRecordID>1072</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:44:37.0000000Z" />
      <EventRecordID>1071</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:14:15.0000000Z" />
      <EventRecordID>1070</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:11:45.0000000Z" />
      <EventRecordID>1069</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:25:19.0000000Z" />
      <EventRecordID>1068</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:28:22.0000000Z" />
      <EventRecordID>1067</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:30:57.0000000Z" />
      <EventRecordID>1066</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T10:17:37.0000000Z" />
      <EventRecordID>1065</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:19:35.0000000Z" />
      <EventRecordID>1064</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:33:58.0000000Z" />
      <EventRecordID>1063</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:53:33.0000000Z" />
      <EventRecordID>1062</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:29:31.0000000Z" />
      <EventRecordID>1061</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:55:45.0000000Z" />
      <EventRecordID>1060</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:23:21.0000000Z" />
      <EventRecordID>1059</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:55:02.0000000Z" />
      <EventRecordID>1058</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:10:44.0000000Z" />
      <EventRecordID>1057</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:11:14.0000000Z" />
      <EventRecordID>1056</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T12:03:02.0000000Z" />
      <EventRecordID>1055</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:36:45.0000000Z" />
      <EventRecordID>1054</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:28:20.0000000Z" />
      <EventRecordID>1053</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T12:17:20.0000000Z" />
      <EventRecordID>1052</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:36:33.0000000Z" />
      <EventRecordID>1051</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:34:13.0000000Z" />
      <EventRecordID>1050</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:55:36.0000000Z" />
      <EventRecordID>1049</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:21:01.0000000Z" />
      <EventRecordID>1048</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:28:37.0000000Z" />
      <EventRecordID>1047</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:28:20.0000000Z" />
      <EventRecordID>1046</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:43:26.0000000Z" />
      <EventRecordID>1045</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:40:47.0000000Z" />
      <EventRecordID>1044</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:18:59.0000000Z" />
      <EventRecordID>1043</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:02:58.0000000Z" />
      <EventRecordID>1042</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:59:56.0000000Z" />
      <EventRecordID>1041</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:44:26.0000000Z" />
      <EventRecordID>1040</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:02:08.0000000Z" />
      <EventRecordID>1039</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:16:45.0000000Z" />
      <EventRecordID>1038</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:01:11.0000000Z" />
      <EventRecordID>1037</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:01:34.0000000Z" />
      <EventRecordID>1036</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:42:46.0000000Z" />
      <EventRecordID>1035</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:05:31.0000000Z" />
      <EventRecordID>1034</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:42:03.0000000Z" />
      <EventRecordID>1033</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T10:37:08.0000000Z" />
      <EventRecordID>1032</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:47:39.0000000Z" />
      <EventRecordID>1031</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:09:43.0000000Z" />
      <EventRecordID>1030</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:16:39.0000000Z" />
      <EventRecordID>1029</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:47:02.0000000Z" />
      <EventRecordID>1028</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:42:27.0000000Z" />
      <EventRecordID>1027</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:55:16.0000000Z" />
      <EventRecordID>1026</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:08:32.0000000Z" />
      <EventRecordID>1025</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:17:48.0000000Z" />
      <EventRecordID>1024</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:06:05.0000000Z" />
      <EventRecordID>1023</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T10:28:13.0000000Z" />
      <EventRecordID>1022</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:29:27.0000000Z" />
      <EventRecordID>1021</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T14:22:06.0000000Z" />
      <EventRecordID>1020</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:04:25.0000000Z" />
      <EventRecordID>1019</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T09:24:52.0000000Z" />
      <EventRecordID>1018</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:13:23.0000000Z" />
      <EventRecordID>1017</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:54:29.0000000Z" />
      <EventRecordID>1016</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:23:11.0000000Z" />
      <EventRecordID>1015</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T13:56:33.0000000Z" />
      <EventRecordID>1014</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T09:06:02.0000000Z" />
      <EventRecordID>1013</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:17:55.0000000Z" />
      <EventRecordID>1012</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:08:38.0000000Z" />
      <EventRecordID>1011</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:56:40.0000000Z" />
      <EventRecordID>1010</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:35:32.0000000Z" />
      <EventRecordID>1009</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:58:10.0000000Z" />
      <EventRecordID>1008</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:22:59.0000000Z" />
      <EventRecordID>1007</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:40:59.0000000Z" />
      <EventRecordID>1006</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:50:14.0000000Z" />
      <EventRecordID>1005</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:05:32.0000000Z" />
      <EventRecordID>1004</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:50:31.0000000Z" />
      <EventRecordID>1003</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:15:06.0000000Z" />
      <EventRecordID>1002</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:03:00.0000000Z" />
      <EventRecordID>1001</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:10:47.0000000Z" />
      <EventRecordID>1000</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T08:49:07.0000000Z" />
      <EventRecordID>999</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:50:07.0000000Z" />
      <EventRecordID>998</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:22:50.0000000Z" />
      <EventRecordID>997</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:02:22.0000000Z" />
      <EventRecordID>996</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:40:50.0000000Z" />
      <EventRecordID>995</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:01:41.0000000Z" />
      <EventRecordID>994</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:11:17.0000000Z" />
      <EventRecordID>993</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:44:27.0000000Z" />
      <EventRecordID>992</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:58:45.0000000Z" />
      <EventRecordID>991</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:21:57.0000000Z" />
      <EventRecordID>990</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:04:54.0000000Z" />
      <EventRecordID>989</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:25:33.0000000Z" />
      <EventRecordID>988</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:33:05.0000000Z" />
      <EventRecordID>987</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:06:53.0000000Z" />
      <EventRecordID>986</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:40:02.0000000Z" />
      <EventRecordID>985</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:04:41.0000000Z" />
      <EventRecordID>984</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T11:06:46.0000000Z" />
      <EventRecordID>983</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:44:23.0000000Z" />
      <EventRecordID>982</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:18:41.0000000Z" />
      <EventRecordID>981</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:39:27.0000000Z" />
      <EventRecordID>980</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:06:18.0000000Z" />
      <EventRecordID>979</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:24:31.0000000Z" />
      <EventRecordID>978</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:28:29.0000000Z" />
      <EventRecordID>977</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:04:34.0000000Z" />
      <EventRecordID>976</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T14:36:20.0000000Z" />
      <EventRecordID>975</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T15:25:13.0000000Z" />
      <EventRecordID>974</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T10:22:27.0000000Z" />
      <EventRecordID>973</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:47:54.0000000Z" />
      <EventRecordID>972</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:37:29.0000000Z" />
      <EventRecordID>971</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T12:05:35.0000000Z" />
      <EventRecordID>970</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:30:07.0000000Z" />
      <EventRecordID>969</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:50:38.0000000Z" />
      <EventRecordID>968</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:40:32.0000000Z" />
      <EventRecordID>967</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:11:25.0000000Z" />
      <EventRecordID>966</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:29:24.0000000Z" />
      <EventRecordID>965</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:34:40.0000000Z" />
      <EventRecordID>964</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T16:33:47.0000000Z" />
      <EventRecordID>963</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:27:48.0000000Z" />
      <EventRecordID>962</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:37:05.0000000Z" />
      <EventRecordID>961</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:54:12.0000000Z" />
      <EventRecordID>960</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:18:32.0000000Z" />
      <EventRecordID>959</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:47:39.0000000Z" />
      <EventRecordID>958</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:39:24.0000000Z" />
      <EventRecordID>957</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:36:29.0000000Z" />
      <EventRecordID>956</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T17:26:24.0000000Z" />
      <EventRecordID>955</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:39:51.0000000Z" />
      <EventRecordID>954</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T13:41:25.0000000Z" />
      <EventRecordID>953</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:35:49.0000000Z" />
      <EventRecordID>952</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T17:00:48.0000000Z" />
      <EventRecordID>951</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:30:22.0000000Z" />
      <EventRecordID>950</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T16:19:48.0000000Z" />
      <EventRecordID>949</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:21:35.0000000Z" />
      <EventRecordID>948</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T13:10:26.0000000Z" />
      <EventRecordID>947</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:05:06.0000000Z" />
      <EventRecordID>946</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:28:55.0000000Z" />
      <EventRecordID>945</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T10:47:21.0000000Z" />
      <EventRecordID>944</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:32:38.0000000Z" />
      <EventRecordID>943</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:06:46.0000000Z" />
      <EventRecordID>942</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:32:41.0000000Z" />
      <EventRecordID>941</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:42:44.0000000Z" />
      <EventRecordID>940</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T15:19:14.0000000Z" />
      <EventRecordID>939</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T14:03:00.0000000Z" />
      <EventRecordID>938</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:33:39.0000000Z" />
      <EventRecordID>937</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:05:17.0000000Z" />
      <EventRecordID>936</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:15:37.0000000Z" />
      <EventRecordID>935</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:58:42.0000000Z" />
      <EventRecordID>934</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:45:04.0000000Z" />
      <EventRecordID>933</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:19:06.0000000Z" />
      <EventRecordID>932</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T08:40:34.0000000Z" />
      <EventRecordID>931</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : lettre_resiliation_modele.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:43:26.0000000Z" />
      <EventRecordID>930</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:34:30.0000000Z" />
      <EventRecordID>929</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:23:01.0000000Z" />
      <EventRecordID>928</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T08:13:32.0000000Z" />
      <EventRecordID>927</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T09:53:39.0000000Z" />
      <EventRecordID>926</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:39:25.0000000Z" />
      <EventRecordID>925</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T11:44:37.0000000Z" />
      <EventRecordID>924</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T15:54:38.0000000Z" />
      <EventRecordID>923</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T16:20:15.0000000Z" />
      <EventRecordID>922</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:21:26.0000000Z" />
      <EventRecordID>921</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:59:37.0000000Z" />
      <EventRecordID>920</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T13:49:29.0000000Z" />
      <EventRecordID>919</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:47:48.0000000Z" />
      <EventRecordID>918</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:32:42.0000000Z" />
      <EventRecordID>917</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:40:58.0000000Z" />
      <EventRecordID>916</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T08:52:01.0000000Z" />
      <EventRecordID>915</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:16:37.0000000Z" />
      <EventRecordID>914</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T17:09:33.0000000Z" />
      <EventRecordID>913</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : declaration_sinistre_auto.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:50:43.0000000Z" />
      <EventRecordID>912</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:03:06.0000000Z" />
      <EventRecordID>911</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:18:46.0000000Z" />
      <EventRecordID>910</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:10:05.0000000Z" />
      <EventRecordID>909</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T14:27:07.0000000Z" />
      <EventRecordID>908</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T16:32:32.0000000Z" />
      <EventRecordID>907</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T16:06:42.0000000Z" />
      <EventRecordID>906</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T15:59:57.0000000Z" />
      <EventRecordID>905</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:10:29.0000000Z" />
      <EventRecordID>904</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : tableau_suivi_sinistres.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T08:57:14.0000000Z" />
      <EventRecordID>903</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:42:15.0000000Z" />
      <EventRecordID>902</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:01:44.0000000Z" />
      <EventRecordID>901</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : processus_gestion_reclamations.docx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:10:28.0000000Z" />
      <EventRecordID>900</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:43:23.0000000Z" />
      <EventRecordID>899</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:24:47.0000000Z" />
      <EventRecordID>898</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : rapport_annuel_risques_2024.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T11:42:57.0000000Z" />
      <EventRecordID>897</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T11:04:34.0000000Z" />
      <EventRecordID>896</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:04:36.0000000Z" />
      <EventRecordID>895</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : audit_interne_conformite_q2_2025.xlsx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T08:53:56.0000000Z" />
      <EventRecordID>894</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T15:58:41.0000000Z" />
      <EventRecordID>893</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : politique_confidentialite_clients.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T10:25:35.0000000Z" />
      <EventRecordID>892</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T10:20:56.0000000Z" />
      <EventRecordID>891</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : formation_conformite_rgpd_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T14:44:51.0000000Z" />
      <EventRecordID>890</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : contrat_assurance_vie_client1234.pdf.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:17:51.0000000Z" />
      <EventRecordID>889</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T09:33:39.0000000Z" />
      <EventRecordID>888</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4663</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T17:16:09.0000000Z" />
      <EventRecordID>887</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith a ouvert le fichier : offre_assurance_habitation_2025.pptx.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T10:27:28.0000000Z" />
      <EventRecordID>886</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:02:32.0000000Z" />
      <EventRecordID>885</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:51:09.0000000Z" />
      <EventRecordID>884</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:58:33.0000000Z" />
      <EventRecordID>883</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T08:17:18.0000000Z" />
      <EventRecordID>882</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:19:46.0000000Z" />
      <EventRecordID>881</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T17:37:10.0000000Z" />
      <EventRecordID>880</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:08:47.0000000Z" />
      <EventRecordID>879</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T13:05:11.0000000Z" />
      <EventRecordID>878</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T12:00:51.0000000Z" />
      <EventRecordID>877</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:26:40.0000000Z" />
      <EventRecordID>876</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T13:12:23.0000000Z" />
      <EventRecordID>875</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T16:11:30.0000000Z" />
      <EventRecordID>874</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T09:12:05.0000000Z" />
      <EventRecordID>873</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T14:07:32.0000000Z" />
      <EventRecordID>872</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T08:43:14.0000000Z" />
      <EventRecordID>871</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:17:15.0000000Z" />
      <EventRecordID>870</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T12:41:29.0000000Z" />
      <EventRecordID>869</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:22:37.0000000Z" />
      <EventRecordID>868</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T09:55:38.0000000Z" />
      <EventRecordID>867</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T11:26:43.0000000Z" />
      <EventRecordID>866</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:30:00.0000000Z" />
      <EventRecordID>865</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T12:49:13.0000000Z" />
      <EventRecordID>864</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T14:49:44.0000000Z" />
      <EventRecordID>863</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T09:22:56.0000000Z" />
      <EventRecordID>862</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T15:36:31.0000000Z" />
      <EventRecordID>861</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:25:52.0000000Z" />
      <EventRecordID>860</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T14:47:36.0000000Z" />
      <EventRecordID>859</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T14:43:52.0000000Z" />
      <EventRecordID>858</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-13T16:28:20.0000000Z" />
      <EventRecordID>857</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T11:44:12.0000000Z" />
      <EventRecordID>856</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:38:15.0000000Z" />
      <EventRecordID>855</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T12:58:49.0000000Z" />
      <EventRecordID>854</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T13:25:02.0000000Z" />
      <EventRecordID>853</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-03T11:06:36.0000000Z" />
      <EventRecordID>852</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T12:24:53.0000000Z" />
      <EventRecordID>851</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T17:59:48.0000000Z" />
      <EventRecordID>850</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T13:40:07.0000000Z" />
      <EventRecordID>849</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T13:12:31.0000000Z" />
      <EventRecordID>848</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:24:48.0000000Z" />
      <EventRecordID>847</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-04T16:16:59.0000000Z" />
      <EventRecordID>846</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-11T10:40:21.0000000Z" />
      <EventRecordID>845</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-12T08:22:00.0000000Z" />
      <EventRecordID>844</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T17:54:29.0000000Z" />
      <EventRecordID>843</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0BDA ProductID=0x0129 DeviceName=Generic USB Hub</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T17:57:33.0000000Z" />
      <EventRecordID>842</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T11:21:45.0000000Z" />
      <EventRecordID>841</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T09:18:37.0000000Z" />
      <EventRecordID>840</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T15:18:48.0000000Z" />
      <EventRecordID>839</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x046D ProductID=0xC534 DeviceName=Logitech USB Receiver</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T13:12:45.0000000Z" />
      <EventRecordID>838</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T11:36:37.0000000Z" />
      <EventRecordID>837</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T09:58:38.0000000Z" />
      <EventRecordID>836</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-10T17:51:05.0000000Z" />
      <EventRecordID>835</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4624</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-06T14:22:23.0000000Z" />
      <EventRecordID>834</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith successfully logged in.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-14T15:03:27.0000000Z" />
      <EventRecordID>833</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T12:24:27.0000000Z" />
      <EventRecordID>832</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">6416</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-05T09:50:52.0000000Z" />
      <EventRecordID>831</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>External device detected: VendorID=0x0781 ProductID=0x5567 DeviceName=SanDisk USB Drive</Data>
    </EventData>
  </Event>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="AuditReport" />
      <EventID Qualifiers="0">4634</EventID>
      <Version>0</Version>
      <Level>4</Level>
      <Task>1</Task>
      <Opcode>0</Opcode>
      <Keywords>0x80000000000000</Keywords>
      <TimeCreated SystemTime="2025-02-07T15:43:23.0000000Z" />
      <EventRecordID>830</EventRecordID>
      <Correlation />
      <Execution ProcessID="1796" ThreadID="0" />
      <Channel>Application</Channel>
      <Security />
    </System>
    <EventData>
      <Data>jane.smith logged off.</Data>
    </EventData>
  </Event>
</Events>
