Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

This is to address attempts to connect to your server via RDP. It will show logon failures.

It may be useful to detect Ransomware attempts

 

# Logonaudit: Script to extract logon failures from a log file.

# By Simon Windisch ict@aldryngton.wokingham.sch.uk

#

# Change $DC to the name of the server with remote access

$DC = "ald-dc1"

#

# Change $Report to an output file

$Report = "k:\logon_Audit.csv"

#

# Change $Time to the number of days (from today) to check back

$Time = 7

 

$Date= Get-date

 

$eventsDC= Get-Eventlog security -Computer $DC -InstanceId 4625 -After (Get-Date).AddDays(-$Time) |

Select TimeGenerated,ReplacementStrings |

% {

New-Object PSObject -Property @{

Target_User = $_.ReplacementStrings[5]

Target_Domain = $_.ReplacementStrings[6]

Workstation_Name = $_.ReplacementStrings[13]

Status = $_.ReplacementStrings[7]

Failure_Reason = $_.ReplacementStrings[8]

Sub_Status = $_.ReplacementStrings[9]

IP_Address = $_.ReplacementStrings[19]

Source_Port = $_.ReplacementStrings[20]

Date = $_.TimeGenerated

}

}

 

$eventsDC | ConvertTo-csv -delimiter ";" -NoTypeInformation | Out-File $Report -Append

Logon_Audit.ps1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...