29.04.2014 Views

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

Spotting the Adversary with Windows Event Log Monitoring

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 24: Subscription Manager Policy Supported OS Version<br />

Figure 25: WinRM Listener Policy Supported OS Version<br />

7.10.1 Installation of WinRM 1.1 on <strong>Windows</strong> Server 2003 R2<br />

The installation of WinRM 1.1 on a <strong>Windows</strong> Server 2003 R2 can be done using an update from<br />

Microsoft. The update URL can be found in <strong>Windows</strong> Remote Management Versions section. It is<br />

possible to install WinRM using <strong>the</strong> <strong>Windows</strong> Server 2003 R2 installation CD; however, this will install<br />

WinRM 0.5. [94] Installing and using WinRM 2.0 is recommended.<br />

8 Works Cited<br />

Distributed Management Task Force, Inc. (2008, 02 12). Web Services for Management (WS-<br />

Management) Specification. Retrieved 10 01, 2012, from Distributed Management Task Force, Inc.:<br />

http://www.dmtf.org/standards/published_documents/DSP0226_1.0.0.pdf<br />

Microsoft Corporation. (2012, 07 12). [MS-CSSP]:Credential Security Support Provider (CredSSP) Procotol.<br />

Retrieved 10 01, 2012, from Microsoft MSDN: http://msdn.microsoft.com/enus/library/cc226764(v=prot.20).aspx<br />

Microsoft Corporation. (2012, 07 15). [MS-ERREF]: <strong>Windows</strong> Error Codes. Retrieved 10 01, 2012, from<br />

Microsoft MSDN: http://msdn.microsoft.com/en-us/library/cc231196.aspx<br />

Microsoft Corporation. (2012, 7 5). [MS-WSMV]: Web Services Management Protocol Extensions for<br />

<strong>Windows</strong> Vista. Retrieved 10 01, 2012, from Microsoft MSDN: http://msdn.microsoft.com/enus/library/cc251526(prot.20).aspx<br />

Microsoft Corporation. (2011, 10 8). An update is available for <strong>the</strong> <strong>Windows</strong> Remote Management<br />

feature in <strong>Windows</strong> Server 2003 and in <strong>Windows</strong> XP. Retrieved 10 01, 2012, from Microsoft Support:<br />

http://support.microsoft.com/kb/KB936059<br />

Microsoft Corporation. (2012, 10 16). Setting up a Source Initiated Subscription. Retrieved 10 01, 2012,<br />

from MSDN Library: http://msdn.microsoft.com/en-us/library/bb870973(VS.85).aspx<br />

94 http://technet.microsoft.com/en-us/library/cc781099.aspx<br />

67

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!