Menu
Security Settings -> Audit Policy -> Audit Process Tracking or useĪdvanced Audit Policy Configuration -> System Audit Policy -> Detailed Tracking. To enable process auditing you should use Group Policy Editor (Press Start then enter “gpedit.msc”) or Local Security Policy (“secpol.msc”) to launch the console. This solution was developed on a Windows 7 machine.ġ/ Setup System Audit to capture Process Creation Events (Event ID 4688)
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |