29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

WinRM Version (KB#) Supported OS KB URIs<br />

WinRM 1.1 (KB936059) <strong>Windows</strong> Server 2003 SP1 http://support.microsoft.com/kb/936059 +<br />

<strong>Windows</strong> Server 2003 SP2<br />

<strong>Windows</strong> XP SP2<br />

<strong>Windows</strong> XP SP3*<br />

WinRM 2.0 (KB968930) <strong>Windows</strong> Server 2003 SP2<br />

<strong>Windows</strong> Server 2008<br />

<strong>Windows</strong> Server 2008 SP2<br />

<strong>Windows</strong> Vista SP1<br />

<strong>Windows</strong> Vista SP2<br />

<strong>Windows</strong> XP SP2*<br />

<strong>Windows</strong> XP SP3<br />

http://support.microsoft.com/kb/968930 +<br />

* Requires Microsoft <strong>Windows</strong> Installer 3.1<br />

* Requires .NET Framework 2.0 SP1<br />

WinRM 3.0 (KB2506146)<br />

<strong>Windows</strong> 7 SP1<br />

<strong>Windows</strong> Server R1 SP1<br />

<strong>Windows</strong> Server 2008 SP2<br />

Table 21: WinRM Version Update URLs<br />

http://support.microsoft.com/kb/2506146 +<br />

* Requires .NET Framework 4.0<br />

* Update comes <strong>with</strong> Release Notes<br />

Microsoft published a knowledge base article (KB936059) [74] and an update for WinRM 1.1. [75] The<br />

knowledge base article offers additional post-installation information to <strong>the</strong> update that is not<br />

mentioned in this document. The actual update can be applied to <strong>Windows</strong> XP SP2, <strong>Windows</strong> Server<br />

2003 SP1, <strong>Windows</strong> Server 2003 SP2, and <strong>Windows</strong> 2003 Server R2.<br />

7.4 WinRM 2.0 Configuration Settings<br />

The quick configuration option of WinRM uses <strong>the</strong> following default configuration settings on <strong>Windows</strong><br />

Server 2008 R2. [26][76] Default values of WinRM configuration settings are shown and referenced in this<br />

document for convenience. [26] The following WinRM command displays <strong>the</strong> configuration setting of WinRM<br />

winrm get winrm/config<br />

It produces <strong>the</strong> following example output:<br />

74 http://support.microsoft.com/kb/936059<br />

75 https://www.microsoft.com/en-us/download/details.aspx?id=21900<br />

76 ([MS-WSMV]: Web Services Management Protocol Extensions for <strong>Windows</strong> Vista, 2012)<br />

52

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!