Regd: A new process has been created Expand / Collapse
Author
Message
Posted 11/5/2014 2:09:04 AM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 2/19/2015 5:29:35 AM
Posts: 10, Visits: 11
Hi:

I am not seeing the event: A new process has been created in our environment.

Kindly clarify on the below points:

1. Can we see this event: 4688 in Domain Controller?

2. If so, kindly let me know the auditing option needs to be enabled?

I want to create the alert for suspicious tools like \\win64dd.exe \\Cachedump. Kindly clarify.

Thanks in Advance!!!

Thanks & Regards,

Sundar

Post #2584
Posted 11/25/2014 5:42:08 PM
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 237, Visits: 0
This event requires success auditing for the following:

Process Tracking
• Process Creation
Post #2589
Posted 12/20/2014 1:55:49 PM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 2/19/2015 5:29:35 AM
Posts: 10, Visits: 11
Thanks for your valuable response.
This event is captured in domain controller? or Workstation? Kindly clarify.

Thanks,
Sundar
Post #2594
Posted 1/28/2015 6:30:04 PM
Supreme Being

Supreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme BeingSupreme Being

Group: Moderators
Last Login: 11/14/2013 3:17:47 PM
Posts: 237, Visits: 0
This event will be captured on the workstation that the process was running on.
Post #2696
« Prev Topic | Next Topic »


Permissions Expand / Collapse

All times are GMT -5:00, Time now is 4:43pm