Volsys Advanced Audit Configuration

Active Directory Domain Security Hardening çalışması kapsamında Domain Controller’lar (Tier 0) için önerilen konfigürasyon aşağıdaki gibidir.

Advanced Audit Configuration
Account Logon
PolicySetting
Audit Credential ValidationFailure
Audit Kerberos Authentication ServiceSuccess, Failure
Audit Kerberos Service Ticket OperationsFailure
Audit Other Account Logon EventsSuccess, Failure
Account Management
PolicySetting
Audit Computer Account ManagementSuccess, Failure
Audit Other Account Management EventsSuccess
Audit Security Group ManagementSuccess, Failure
Audit User Account ManagementSuccess, Failure
Detailed Tracking
PolicySetting
Audit DPAPI ActivitySuccess, Failure
Audit PNP ActivitySuccess
Audit Process CreationSuccess
DS Access
PolicySetting
Audit Directory Service AccessFailure
Audit Directory Service ChangesSuccess
Logon/Logoff
PolicySetting
Audit Account LockoutFailure
Audit Group MembershipSuccess
Audit LogoffSuccess
Audit LogonSuccess, Failure
Audit Other Logon/Logoff EventsSuccess, Failure
Audit Special LogonSuccess, Failure
Object Access
PolicySetting
Audit Application GeneratedSuccess
Audit Detailed File ShareFailure
Audit File ShareSuccess, Failure
Audit File SystemSuccess
Audit Filtering Platform ConnectionFailure
Audit Filtering Platform Packet DropSuccess
Audit Kernel ObjectSuccess
Audit Other Object Access EventsSuccess, Failure
Audit RegistrySuccess
Audit Removable StorageSuccess, Failure
Audit SAMSuccess
Policy Change
PolicySetting
Audit Audit Policy ChangeSuccess, Failure
Audit Authentication Policy ChangeSuccess, Failure
Audit Filtering Platform Policy ChangeSuccess
Audit MPSSVC Rule-Level Policy ChangeSuccess, Failure
Audit Other Policy Change EventsFailure
Privilege Use
PolicySetting
Audit Other Privilege Use EventsSuccess
Audit Sensitive Privilege UseSuccess, Failure
System
PolicySetting
Audit Other System EventsSuccess
Audit Security State ChangeSuccess, Failure
Audit Security System ExtensionSuccess
Audit System IntegritySuccess, Failure