[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

243238

 
 

909

 
 

192833

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CCE
view XML

CCE-37361-3

Platform: win2012r2Date: (C)2015-10-08   (M)2022-10-10



Audit Policy: DS Access: Detailed Directory Service Replication This subcategory reports detailed information about the information replicating between domain controllers. These events can be very high in volume. Events for this subcategory include: ? 4928: An Active Directory replica source naming context was established. ? 4929 : An Active Directory replica source naming context was removed. ? 4930 : An Active Directory replica source naming context was modified. ? 4931 : An Active Directory replica destination naming context was modified. ? 4934 : Attributes of an Active Directory object were replicated. ? 4935 : Replication failure begins. ? 4936 : Replication failure ends. ? 4937 : A lingering object was removed from a replica. Refer to the Microsoft Knowledgebase article ?Description of security events in Windows Vista and in Windows Server 2008? for the most recent information about this setting: http://support.microsoft.com/default.aspx/kb/947226.


Parameter:


Technical Mechanism:

(1) GPO: Computer Configuration\Windows Settings\Security Settings\Advanced Audit Policy Configuration\Audit Policies\DS Access!Audit Policy: DS Access: Detailed Directory Service Replication (2) WMI: ###

CCSS Severity:CCSS Metrics:
CCSS Score : Attack Vector:
Exploit Score: Attack Complexity:
Impact Score: Privileges Required:
Severity: User Interaction:
Vector: Scope:
 Confidentiality:
 Integrity:
 Availability:
  

References:
Resource IdReference
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:22760
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:22760
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:22760
SCAP Repo OVAL Definitionoval:org.secpod.oval:def:22760


OVAL    1
oval:org.secpod.oval:def:22760

© SecPod Technologies