Hier werden die Unterschiede zwischen zwei Versionen angezeigt.
| Beide Seiten der vorigen Revision Vorhergehende Überarbeitung Nächste Überarbeitung | Vorhergehende Überarbeitung | ||
|
active_directory [2025/03/29 20:49] jango [Event-Log] |
active_directory [2025/10/19 21:45] (aktuell) jango [Links] |
||
|---|---|---|---|
| Zeile 2: | Zeile 2: | ||
| Siehe auch [[coding: | Siehe auch [[coding: | ||
| + | |||
| + | < | ||
| + | repadmin /syncall /AeD | ||
| + | repadmin /syncall /d /e < | ||
| + | dnscmd /zoneinfo domain.local | ||
| + | </ | ||
| =====Reversible Encryption===== | =====Reversible Encryption===== | ||
| Zeile 70: | Zeile 76: | ||
| * PDC Emulator | * PDC Emulator | ||
| * Kein eigener Schema Master oder Domain Naming Master. Diese Rollen werden nur in der Stammdomäne benötigt. | * Kein eigener Schema Master oder Domain Naming Master. Diese Rollen werden nur in der Stammdomäne benötigt. | ||
| + | =====Protokolle===== | ||
| + | |||
| + | * [[LDAP]] | ||
| + | * [[Kerberos]] | ||
| + | * [[SMB]]/ | ||
| + | * [[DNS]] | ||
| + | |||
| ====SysVol==== | ====SysVol==== | ||
| Zeile 242: | Zeile 255: | ||
| * [[DNS]] Server | * [[DNS]] Server | ||
| * [[DHCP]] Server | * [[DHCP]] Server | ||
| - | * Active Directory Certificate Services | + | * [[ADCS]] (Active Directory Certificate Services) |
| * Remote Access Server (RAS) - [[VPN]] | * Remote Access Server (RAS) - [[VPN]] | ||
| * Microsoft Active Directory Federation Services ([[adfs|ADFS]]) - Verschlüsselung, | * Microsoft Active Directory Federation Services ([[adfs|ADFS]]) - Verschlüsselung, | ||
| Zeile 268: | Zeile 281: | ||
| ====Event-Log==== | ====Event-Log==== | ||
| - | Wichtige Event IDs | + | Wichtige Event IDs (unsortiert) [[todo]] |
| ^ID^Beschreibung^ | ^ID^Beschreibung^ | ||
| Zeile 292: | Zeile 305: | ||
| |4738|A user account was changed.| | |4738|A user account was changed.| | ||
| |4740|A user account was locked out.| | |4740|A user account was locked out.| | ||
| - | |4741|A computer account was changed.| | + | |4741|A computer account was chreated.| |
| - | |4742|A computer account was changed??| | + | |4742|A computer account was changed.| |
| |4743|A computer account was deleted| | |4743|A computer account was deleted| | ||
| |4744|A security-disabled local group was created.| | |4744|A security-disabled local group was created.| | ||
| Zeile 333: | Zeile 346: | ||
| |4788|A nonmember was removed from a basic application group.| | |4788|A nonmember was removed from a basic application group.| | ||
| + | 4698: A scheduled task was created. | ||
| + | 4699: A scheduled task was deleted. | ||
| + | 4700: A scheduled task was enabled. | ||
| + | 4701: A scheduled task was disabled. | ||
| + | 4702: A scheduled task was updated. | ||
| + | |||
| + | 1002: malware scan stopped before completing scan | ||
| + | 1003: malware scan paused | ||
| + | 1005: malware scan failed | ||
| + | 1006, 1116: malware or unwanted software detected | ||
| + | 1007, 1117: action to protect system performed | ||
| + | 1008, 1118: action to protect system failed | ||
| + | 1009: item restored from quarantine | ||
| + | 1012: unable to delete item in quarantine | ||
| + | 1015: suspicious behavior detected | ||
| + | 1119: critical error occurred when taking action | ||
| [[ToDo]] [[https:// | [[ToDo]] [[https:// | ||
| - | Group managment | + | ===User & Group Managment=== |
| + | |||
| + | Computerkonfiguration -> Windows-Einstellungen -> Sicherheitseinstellungen -> Erweiterte Überwachungsrichtlinien -> Kontenverwaltung | ||
| + | |||
| + | * Benutzeranmeldeereignisse überwachen(für Benutzeranmeldungen und -abmeldungen) | ||
| + | * Benutzer- und Gruppenänderungen überwachen (Für Änderungen an Benutzerkonten und Gruppenmitgliedschaften) | ||
| + | |||
| + | Überwachungsrichtlinie für " | ||
| + | |||
| + | Computerkonfiguration -> Windows-Einstellungen -> Sicherheitseinstellungen -> Erweiterte Überwachungsrichtlinien -> Objektzugriff | ||
| + | |||
| + | Aktiviere: Zugriff auf Datei-/ | ||
| + | |||
| + | User Managment | ||
| + | |||
| + | ^Event ID^Beschreibung^ | ||
| + | |4720|A user account was created (Benutzerkonto erstellt)| | ||
| + | |4726|A user account was deleted (Benutzerkonto gelöscht)| | ||
| + | |4738|A user account was changed (Allgemeine Änderungen am Benutzerkonto)| | ||
| + | |4767|A user account was unlocked (Konto entsperrt)| | ||
| + | |4740|A user account was locked out (Konto gesperrt)| | ||
| + | |4725|A user account was disabled (Konto deaktiviert)| | ||
| + | |4722|A user account was enabled (Konto aktiviert)| | ||
| + | |4723|An attempt was made to change an account' | ||
| + | |4724|An attempt was made to reset an account' | ||
| + | |4728|A member was added to a security-enabled global group| | ||
| + | |4729|A member was removed from a security-enabled global group| | ||
| + | |4732|A member was added to a security-enabled local group| | ||
| + | |4733|A member was removed from a security-enabled local group| | ||
| + | |4756|A member was added to a security-enabled universal group| | ||
| + | |4757|A member was removed from a security-enabled universal group| | ||
| + | |||
| + | |||
| + | |||
| + | Security Groups | ||
| ^Event ID^Beschreibung^ | ^Event ID^Beschreibung^ | ||
| |4727|A security-enabled global group was created| | |4727|A security-enabled global group was created| | ||
| Zeile 351: | Zeile 414: | ||
| |4757|A security-enabled universal group was deleted| | |4757|A security-enabled universal group was deleted| | ||
| + | Distribution Groups | ||
| + | ^Event ID^Beschreibung^ | ||
| + | |4744|A distribution group was created| | ||
| + | |4745|A member was added to a distribution group| | ||
| + | |4746|A member was removed from a distribution group| | ||
| + | |4747|A distribution group was deleted| | ||
| + | |||
| + | |||
| + | ===NTFS Berechtigungen=== | ||
| + | |||
| + | Objektzugriffsüberwachung muss aktiviert sein. | ||
| + | |||
| + | Gruppenrichtlinien: | ||
| + | |||
| + | Aktiviere die Option: Datei- und Ordnerschutz überwachen | ||
| + | |||
| + | Alternativ in klassischen Richtlinien: | ||
| + | |||
| + | |||
| + | Gehe zum Ordner oder Laufwerk, das du überwachen möchtest: Rechtsklick -> Eigenschaften -> Sicherheit -> Erweitert -> Überwachung | ||
| + | |||
| + | Füge " | ||
| + | |||
| + | Wähle die Berechtigungen aus, die überwacht werden sollen, z. B.: | ||
| + | |||
| + | * Lesen | ||
| + | * Ändern | ||
| + | * Schreiben | ||
| + | * Löschen | ||
| + | * Erstellen | ||
| + | |||
| + | Wenn du alle Zugriffsarten überwachen möchtest, wähle " | ||
| + | |||
| + | ^Event ID^Beschreibung^ | ||
| + | |4670|Permissions on an object were changed (Änderung von NTFS-Berechtigungen)| | ||
| + | |4674|An operation was attempted on a privileged object (Änderung an einem geschützten Objekt)| | ||
| + | |5145|A network share object was checked to see whether client can be granted desired access (Prüfung von Freigabeberechtigungen)| | ||
| + | |4660|An object was deleted (Objekt gelöscht, z.B. eine Datei oder ein Ordner)| | ||
| + | |4663|An attempt was made to access an object (Allgemeiner Objektzugriff, | ||
| + | |4662|An operation was performed on an object (Änderung des Besitzes von Dateien/ | ||
| + | |4656|A handle to an object was requested (Zugriffsversuch auf ein Objekt mit Berechtigungsänderung)| | ||
| + | |||
| + | ===SMB Share Berechtigungen=== | ||
| + | |||
| + | untested | ||
| + | |||
| + | ^Event ID^Beschreibung^ | ||
| + | |5142|A network share object was added.| | ||
| + | |5143|A network share object was modified.| | ||
| + | |5144|A network share object was deleted.| | ||
| + | ===Powershell Script=== | ||
| <code powershell> | <code powershell> | ||
| # Definieren Sie den Zeitraum für die Überwachung (z.B. die letzten 7 Tage) | # Definieren Sie den Zeitraum für die Überwachung (z.B. die letzten 7 Tage) | ||
| Zeile 401: | Zeile 515: | ||
| Get-ADForest | Select-Object SchemaMaster, | Get-ADForest | Select-Object SchemaMaster, | ||
| </ | </ | ||
| + | |||
| + | =====Linux Join===== | ||
| + | |||
| + | ====Ubuntu/ | ||
| + | |||
| + | < | ||
| + | sudo apt install -y sssd realmd libnss-sss libpam-sss adcli | ||
| + | </ | ||
| + | |||
| + | Siehe [[realmd]] | ||
| + | ====RHEL==== | ||
| + | |||
| + | < | ||
| + | </ | ||
| + | |||
| + | =====Password Filter===== | ||
| + | |||
| + | Siehe [[https:// | ||
| + | |||
| =====Links===== | =====Links===== | ||