[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

111666

 
 

909

 
 

87321

 
 

136

Paid content will be excluded from the download.


Download | Alert*
OVAL

Ensure Audit Success for 'Audit Policy: Detailed Tracking: Process Creation'

ID: oval:org.secpod.oval:def:35502Date: (C)2016-06-10   (M)2018-03-24
Class: COMPLIANCEFamily: windows




This subcategory reports the creation of a process and the name of the program or user that created it. Note: These events now get audited earlier than in previous versions of Windows. The creation of smss.exe and other early processes is now audited. Default settings that cannot be altered until after Lsass starts. Events for this subcategory include: - 4688: A new process has been created. - 4696: A primary token was assigned to process. Refer to the Microsoft Knowledgebase article 'Description of security events in Windows Vista and in Windows Server 2008' for the most recent information about this setting: http://support.microsoft.com/kb/947226.

Platform:
Microsoft Windows 10
Reference:
CCE-43062-9
CCE    1
CCE-43062-9

© SecPod Technologies