Skip to main content
img fix
Source Link
Clayton
  • 527
  • 2
  • 8
  1. Edit local policy and enable "Audit Process Tracking" (secpol.msc)

  2. Install KB3004375 and reboot https://support.microsoft.com/en-us/kb/3004375

  3. Enable Audit Process Creation/Include CLI (gpedit.msc)

  4. If you're using Win7 Home instead of professional you won't have gpedit.msc. Regedit to HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit. Set key ProcessCreationIncludeCmdLine_Enabled = 1

  5. Run the program that launches FFMEG

  6. Review the security event log for event ID 4688

apt apc 4688auditPol

auditCli

4688

  1. Edit local policy and enable "Audit Process Tracking" (secpol.msc)

  2. Install KB3004375 and reboot https://support.microsoft.com/en-us/kb/3004375

  3. Enable Audit Process Creation/Include CLI (gpedit.msc)

  4. If you're using Win7 Home instead of professional you won't have gpedit.msc. Regedit to HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit. Set key ProcessCreationIncludeCmdLine_Enabled = 1

  5. Run the program that launches FFMEG

  6. Review the security event log for event ID 4688

apt apc 4688

  1. Edit local policy and enable "Audit Process Tracking" (secpol.msc)

  2. Install KB3004375 and reboot https://support.microsoft.com/en-us/kb/3004375

  3. Enable Audit Process Creation/Include CLI (gpedit.msc)

  4. If you're using Win7 Home instead of professional you won't have gpedit.msc. Regedit to HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit. Set key ProcessCreationIncludeCmdLine_Enabled = 1

  5. Run the program that launches FFMEG

  6. Review the security event log for event ID 4688

auditPol

auditCli

4688

Source Link
Clayton
  • 527
  • 2
  • 8

  1. Edit local policy and enable "Audit Process Tracking" (secpol.msc)

  2. Install KB3004375 and reboot https://support.microsoft.com/en-us/kb/3004375

  3. Enable Audit Process Creation/Include CLI (gpedit.msc)

  4. If you're using Win7 Home instead of professional you won't have gpedit.msc. Regedit to HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Audit. Set key ProcessCreationIncludeCmdLine_Enabled = 1

  5. Run the program that launches FFMEG

  6. Review the security event log for event ID 4688

apt apc 4688