29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

5985:TCP:192.168.1.2:Enabled:<strong>Windows</strong> Remote Management<br />

This rule ensures that connections between <strong>Windows</strong> XP clients using WinRM are blocked.<br />

2.7.2 Collector Firewall Modification<br />

As done in <strong>the</strong> Source Firewall Modifications section, repeat <strong>the</strong> steps for <strong>the</strong> predefined WinRM rule.<br />

Setting <strong>the</strong> Predefined set of computers option to Local subnet is recommended. This rule can be<br />

changed to best suit your environment.<br />

Figure 20: The <strong>Event</strong> Collector Firewall allowing Local subnet to Connect<br />

Group Policy Firewall Problem<br />

While viewing a subscription in <strong>Event</strong> Viewer, <strong>the</strong> following error may appear. As <strong>the</strong> dialog states, a<br />

firewall exception needs to be applied. Verify that when you enabled <strong>the</strong> predefined firewall rules via a<br />

Group Policy that <strong>the</strong> firewall profile for <strong>the</strong> rule is enabled as well.<br />

A more detailed error message can be obtained by providing <strong>the</strong> name of <strong>the</strong> desired subscription<br />

(subscriptionID):<br />

wecutil get-subscriptionruntimestatus SubscriptionID<br />

2.8 Disabling WinRM and <strong>Windows</strong> Collector Service<br />

<strong>Windows</strong> Remote Management (WinRM) and <strong>Event</strong> Forwarding can be stopped from operating in <strong>the</strong><br />

network. The collector needs to halt and disable <strong>the</strong> <strong>Windows</strong> <strong>Event</strong> Collector and <strong>Windows</strong> Remote<br />

Management services. These services can be stopped in <strong>the</strong> Services Microsoft Management Console<br />

(MMC) snap-in. The subscriptions created in <strong>the</strong> <strong>Event</strong> Viewer should be disabled on <strong>the</strong> log aggregation<br />

server.<br />

To disable collection of events on <strong>the</strong> server:<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!