【问题标题】:Is there a native option to log local-code execution?是否有记录本地代码执行的本机选项?
【发布时间】:2022-06-30 16:36:03
【问题描述】:

我曾想过使用 GPO 记录客户端计算机中代码的执行情况,但我无法找到方法。

感谢您的建议。

【问题讨论】:

    标签: active-directory azure-active-directory windows-server-2012 windows-server


    【解决方案1】:

    您可以使用组策略设置Event log security locally

    选择 开始-> 运行输入 _gpedit.msc ->组策略编辑器->Windows设置->安全设置 strong>,-> 本地策略->安全选项.->双击事件日志 :应用程序日志 SDDL 键入 SDDL 字符串然后双击 事件日志:系统日志 SDDL-> 键入 SDDL 字符串以确保日志安全并确定

    MS15-011: Vulnerability in Group Policy could allow remote code execution: February 10, 2015 (microsoft.com)

    或者

    如果您在 Active Directory 中的用户帐户可以登录客户端计算机转到 Active Directory 用户和计算机中的“帐户”选项卡,单击“登录到...”按钮以通过本地访问网络登录RDP。检查此解决方法以修改 GPO

    开始->程序->管理工具->域控制器安全策略->双击安全设置->双击本地策略->用户权限分配->策略下->本地登录- > 添加 -> 好的

    workstation logons with Group Policy

    供您参考:

    Group Policy Settings Used in Windows Authentication

    Top 10 Most Important Group Policy Settings for Preventing Security Breaches (lepide.com)

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2016-02-29
      • 1970-01-01
      • 2020-08-21
      • 1970-01-01
      • 2013-03-02
      • 2014-04-10
      • 2011-06-23
      • 1970-01-01
      相关资源
      最近更新 更多