Direct Inward Dialing: +1 408 916 9892
An IT administrator in any organization is responsible for tracking user activity and ensuring there are no insider threats. To carry out these responsibilities, they must monitor what applications or software an employee accesses on their workstation; if this isn't tracked, an employee could intentionally or unintentionally run any sort of malware, leading not only to device compromise, but also potentially put the entire enterprise network in danger. In an Active Directory (AD) environment, this tracking is referred to as auditing process tracking. Read on to find out how to audit process tracking.
Perform the following actions on the domain controller (DC):
Once this policy is enabled, events are logged in the DC's security log whenever a process has been created or has exited.
Once the above steps are complete, events will be stored in the event log. This can be viewed in the Event Viewer by following the steps below:
Event ID | Subcategory | Event Type | Description |
---|---|---|---|
4688 | Audit Process Creation | Success | A new process has been created. |
4696 | Audit Process Creation | Success | A primary token was assigned to process. |
4689 | Audit Process Termination | Success | A process has exited. |
Event 4688 is logged when a process is created. The following details are logged in the event properties:
The above method is unrealistic when you have to deal with thousands of devices in an organization, as an administrator would have to manually look up each event to view its details.
ADAudit Plus, a comprehensive AD auditing tool, enables admins to effortlessly audit process creation and termination events. They can also keep track of all scheduled task creation, deletion, and modifications made to them with ease.
You can also keep track of process termination. Navigate to Server Audit → Process Tracking → New Process Exited.
Advantages of using ADAudit Plus over native auditing:
Our team will be in touch with you shortly.
Sign up for a free live demo and discover why 15,000+ customers trust ManageEngine ADAudit Plus with their Active Directory security.