Audit Process Creation (592/4688)

在启用了"审核进程创建"时记录4688的情况下(系统默认是关闭的,需要手动开启),Windows 7Windows Server 2008及以上版本,会在每次创建一个进程时会把事件以Event ID4688记录到windows安全日志中

Windows XP/2003Event ID592

开启:Edit Default Domain Policy -> Policy location: Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Advanced Audit Configuration -> Detailed Tracking

策略名称: Audit Process Creation

image

查看ID为4688的安全事件:

image

命令行获取:

wevtutil qe security /rd:true /f:text /q:"Event[System[(EventID=4688)]]"

image

零组资料文库 all right reserved,powered by 0-sec.org未经授权禁止转载 2020-01-30 00:12:45

results matching ""

    No results matching ""