enabling audit process tracking policy posted on Sunday, July 24, 2005

Enable the Audit process tracking audit policy for the desired computers. You'll find this setting in any Group Policy Object (GPO) under Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy in the Group Policy Management Console (GPMC). Then start monitoring for event ID 592 (A new process has been created), which Windows logs whenever a new executable is started. This event reports the full path of the program and the user who started the program, as Figure 1 shows. You can figure out when the program ended by looking in the log for an occurrence of event ID 593 (A process has exited) with the same Process ID value
-
Finding the Programs Executed on a System
logparser "select TimeGenerated, RESOLVE_SID(REPLACE_CHR(EXTRACT_TOKEN(Strings,3,''),'{}%','')) as User, EXTRACT_TOKEN(Strings,1,'') as Program from security where eventid=592"

-
http://www.ultimatewindowssecurity.com/encyclopedia.html

--


- Links -

home | mail | radio | flickr | translation

- contact -

singtel | starbub | M1

- previous entries -

Sex Shop @bugis
Orwellian Library
Scribbled papers
147
Belief
what more is required
serfs
serfs
ills of conscription
Bit Torrent

- archives -

December 2004
January 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
December 2006

- what I want -

hamsterdamned in hell
practical english usage
china - a century of revolution
venitha's reading list
--