SimonWindisch Posted October 10, 2016 Posted October 10, 2016 This is to address attempts to connect to your server via RDP. It will show logon failures. It may be useful to detect Ransomware attempts # Logonaudit: Script to extract logon failures from a log file. # By Simon Windisch ict@aldryngton.wokingham.sch.uk # # Change $DC to the name of the server with remote access $DC = "ald-dc1" # # Change $Report to an output file $Report = "k:\logon_Audit.csv" # # Change $Time to the number of days (from today) to check back $Time = 7 $Date= Get-date $eventsDC= Get-Eventlog security -Computer $DC -InstanceId 4625 -After (Get-Date).AddDays(-$Time) | Select TimeGenerated,ReplacementStrings | % { New-Object PSObject -Property @{ Target_User = $_.ReplacementStrings[5] Target_Domain = $_.ReplacementStrings[6] Workstation_Name = $_.ReplacementStrings[13] Status = $_.ReplacementStrings[7] Failure_Reason = $_.ReplacementStrings[8] Sub_Status = $_.ReplacementStrings[9] IP_Address = $_.ReplacementStrings[19] Source_Port = $_.ReplacementStrings[20] Date = $_.TimeGenerated } } $eventsDC | ConvertTo-csv -delimiter ";" -NoTypeInformation | Out-File $Report -Append Logon_Audit.ps1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now