29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

The Enabled registry value should have <strong>the</strong> value of 1 to enable <strong>the</strong> log. There is no GPO policy to enable<br />

a specific log; however, it is possible to use <strong>the</strong> Group Policy Preferences to update a registry value via<br />

GPO.<br />

WinRM is not permitted to read <strong>the</strong> CAPI2 event log as only <strong>the</strong> built-in administrators and <strong>the</strong><br />

Au<strong>the</strong>nticated Users groups can. Updating <strong>the</strong> ChannelAccess registry value to include <strong>the</strong> <strong>Event</strong> <strong>Log</strong><br />

Readers group is recommended. This grants <strong>the</strong> members of <strong>the</strong> <strong>Event</strong> <strong>Log</strong> Readers group permission to<br />

read <strong>the</strong> CAPI2 operational log. Using <strong>the</strong> same method for enabling <strong>the</strong> CAPI2 log, append (A;;CC;;;S-1-<br />

5-32-573) to <strong>the</strong> existing SDDL. The complete SDDL should be:<br />

O:BAG:SYD:(A;;0x7;;;BA)(A;;0x2;;;AU)(A;;CC;;;S-1-5-32-573)<br />

<strong>Log</strong>on Using Explicit Credentials (ExpCreds.xml)<br />

<br />

ExpCreds<br />

SourceInitiated<br />

true<br />

http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />

Custom<br />

<br />

1<br />

1000<br />

<br />

<br />

<br />

<br />

<br />

<br />

*[System[(Level=4 or Level=0) and (<strong>Event</strong>ID=4648)]]<br />

<br />

<br />

]]><br />

true<br />

http<strong>Event</strong>s<br />

Forwarded<strong>Event</strong>s<br />

<br />

<br />

<br />

Account Locked Out (LockedOut.xml)<br />

<br />

LockedOut<br />

SourceInitiated<br />

User Account Locked Outtrue<br />

http://schemas.microsoft.com/wbem/wsman/1/windows/<strong>Event</strong><strong>Log</strong><br />

Custom<br />

<br />

1<br />

1000<br />

<br />

<br />

<br />

<br />

<br />

*[System[(Level=4 or Level=0) and (<strong>Event</strong>ID=4740)]]<br />

<br />

]]><br />

true<br />

http<strong>Event</strong>s<br />

Forwarded<strong>Event</strong>s<br />

<br />

<br />

<br />

Account <strong>Log</strong>ons (<strong>Log</strong>ons.xml)<br />

40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!