Sunday, January 19, 2020

Windows Server System Audit Policy

For every task we do corresponding logs are generated. However, not all events in windows events are important. So, we need to make sure that we have optimum set of auditing enabled in our infrastructure. This will allow us to do much of forensic analysis by using simple tool like SIEM. So, here are the list of audit policy that needs to be atleast configured in your network. The list below is the minimum set of recommended settings and it can vary according to your organizations needs. Feel free to edit according to your requirements.

System audit policy
Category/SubcategorySetting
System
Security System ExtensionNo Auditing
System IntegritySuccess and Failure
IPsec DriverNo Auditing
Other System EventsSuccess and Failure
Security State ChangeSuccess
Logon/Logoff
LogonSuccess and Failure
LogoffSuccess
Account LockoutSuccess
IPsec Main ModeNo Auditing
IPsec Quick ModeNo Auditing
IPsec Extended ModeNo Auditing
Special LogonSuccess
Other Logon/Logoff EventsNo Auditing
Network Policy ServerSuccess and Failure
Object Access
File SystemSuccess and Failure
RegistrySuccess and Failure
Kernel ObjectNo Auditing
SAMNo Auditing
Certification ServicesNo Auditing
Application GeneratedNo Auditing
Handle ManipulationNo Auditing
File ShareSuccess and Failure
Filtering Platform Packet DropNo Auditing
Filtering Platform ConnectionNo Auditing
Other Object Access EventsNo Auditing
Privilege Use
Sensitive Privilege UseNo Auditing
Non Sensitive Privilege UseNo Auditing
Other Privilege Use EventsNo Auditing
Detailed Tracking
Process TerminationNo Auditing
DPAPI ActivityNo Auditing
RPC EventsNo Auditing
Process CreationNo Auditing
Policy Change
Audit Policy ChangeSuccess
Authentication Policy ChangeSuccess
Authorization Policy ChangeNo Auditing
MPSSVC Rule-Level Policy ChangeNo Auditing
Filtering Platform Policy ChangeNo Auditing
Other Policy Change EventsNo Auditing
Account Management
User Account ManagementSuccess
Computer Account ManagementSuccess
Security Group ManagementSuccess
Distribution Group ManagementNo Auditing
Application Group ManagementNo Auditing
Other Account Management EventsNo Auditing
DS Access
Directory Service ChangesSuccess and Failure
Directory Service ReplicationNo Auditing
Detailed Directory Service ReplicationNo Auditing
Directory Service AccessSuccess
Account Logon
Kerberos Service Ticket OperationsSuccess
Other Account Logon EventsNo Auditing
Kerberos Authentication ServiceSuccess
Credential ValidationSuccess
The launchpad to a career in IT. This program is designed to take beginner learners to job readiness in about eight months.

No comments:

Post a Comment