When executing powershell or invoke-command scripts the Change Auditor does not record anything
When executing powershell or invoke-command scripts the Change Auditor does not record anything
today is very easy write powershell scripts that can do unauthorized changes and exists tools development to exploit vulnerabilities and execute then a computer was exposed.
I consider very important that Change Auditor agent can capture any event that can help to prevent any attack.
I would look at it this way. The story is complex and we need to consider the whole picture with following points of control:
#1. Right to execute the script/ACL/permissions layer: Local Admin, OS rights (Logon as Batch Job, As Service) - controlled by GPO
#2. Log the execution actions on Server: Events (Logon as Batch Job, As Service), TS Logon, Interactive Logon.
#2.1 Log access on Resources: File Access on Share by the script, other servers$ shares etc...