Sunday, September 25, 2005
track the programs that a user executes on his or her workstation or the programs being executed on a server?
          Enable the Audit process tracking audit policy for the desired computers. You'll find this setting in any Group Policy Object (GPO) under Computer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy in the Group Policy Management Console (GPMC). Then start monitoring for event ID 592 (A new process has been created), which Windows logs whenever a new executable is started. This event reports the full path of the program and the user who started the program, as Figure 1 shows. You can figure out when the program ended by looking in the log for an occurrence of event ID 593 (A process has exited) with the same Process ID value. For more information about these events, see my Windows Security Log Encyclopedia at http://www.ultimatewindowssecurity.com/encyclopedia.html. . . . 
http://www.ultimatewindowssecurity.com/encyclopedia.html
          
		
 
  
http://www.ultimatewindowssecurity.com/encyclopedia.html

