diff --git a/WELAVerboseSecAudit.psm1 b/WELAVerboseSecAudit.psm1 index beddc065..fbe98a48 100644 --- a/WELAVerboseSecAudit.psm1 +++ b/WELAVerboseSecAudit.psm1 @@ -28,48 +28,48 @@ function ShowVerboseSecurity { [array]$rules ) - $m_credential_validation = CountRules -guid "" -rules $rules - $m_kerberos_authentication_service = CountRules -guid "" -rules $rules - $m_kerberos_sevice_ticket_operations = CountRules -guid "" -rules $rules - $m_computer_account_management = CountRules -guid "" -rules $rules - $m_other_account_management = CountRules -guid "" -rules $rules - $m_security_group_management = CountRules -guid "" -rules $rules - $m_user_account_management = CountRules -guid "" -rules $rules - $m_plug_and_play_events = CountRules -guid "" -rules $rules - $m_process_creation = CountRules -guid "" -rules $rules - $m_process_termination = CountRules -guid "" -rules $rules - $m_rpc_events = CountRules -guid "" -rules $rules - $m_token_right_adjusted_events = CountRules -guid "" -rules $rules - $m_directory_service_access = CountRules -guid "" -rules $rules - $m_account_lockout = CountRules -guid "" -rules $rules - $m_logoff = CountRules -guid "" -rules $rules - $m_logon = CountRules -guid "" -rules $rules - $m_other_logon_logoff_events = CountRules -guid "" -rules $rules - $m_special_logon = CountRules -guid "" -rules $rules - $m_certification_services = CountRules -guid "" -rules $rules - $m_detailed_file_share = CountRules -guid "" -rules $rules - $m_file_share = CountRules -guid "" -rules $rules - $m_file_system = CountRules -guid "" -rules $rules + $m_credential_validation = CountRules -guid "0CCE923F-69AE-11D9-BED3-505054503030" -rules $rules + $m_kerberos_authentication_service = CountRules -guid "0CCE9242-69AE-11D9-BED3-505054503030" -rules $rules + $m_kerberos_sevice_ticket_operations = CountRules -guid "0CCE9240-69AE-11D9-BED3-505054503030" -rules $rules + $m_computer_account_management = CountRules -guid "0CCE9236-69AE-11D9-BED3-505054503030" -rules $rules + $m_other_account_management = CountRules -guid "0CCE923A-69AE-11D9-BED3-505054503030" -rules $rules + $m_security_group_management = CountRules -guid "0CCE9237-69AE-11D9-BED3-505054503030" -rules $rules + $m_user_account_management = CountRules -guid "0CCE9235-69AE-11D9-BED3-505054503030" -rules $rules + $m_plug_and_play_events = CountRules -guid "0CCE9248-69AE-11D9-BED3-505054503030" -rules $rules + $m_process_creation = CountRules -guid "0CCE922B-69AE-11D9-BED3-505054503030" -rules $rules + $m_process_termination = CountRules -guid "0CCE922C-69AE-11D9-BED3-505054503030" -rules $rules + $m_rpc_events = CountRules -guid "0CCE922E-69AE-11D9-BED3-505054503030" -rules $rules + $m_token_right_adjusted_events = CountRules -guid "0CCE924A-69AE-11D9-BED3-505054503030" -rules $rules + $m_directory_service_access = CountRules -guid "0CCE923B-69AE-11D9-BED3-505054503030" -rules $rules + $m_account_lockout = CountRules -guid "0CCE9217-69AE-11D9-BED3-505054503030" -rules $rules + $m_logoff = CountRules -guid "0CCE9216-69AE-11D9-BED3-505054503030" -rules $rules + $m_logon = CountRules -guid "0CCE9215-69AE-11D9-BED3-505054503030" -rules $rules + $m_other_logon_logoff_events = CountRules -guid "0CCE921C-69AE-11D9-BED3-505054503030" -rules $rules + $m_special_logon = CountRules -guid "0CCE921B-69AE-11D9-BED3-505054503030" -rules $rules + $m_certification_services = CountRules -guid "0CCE9221-69AE-11D9-BED3-505054503030" -rules $rules + $m_detailed_file_share = CountRules -guid "0CCE9244-69AE-11D9-BED3-505054503030" -rules $rules + $m_file_share = CountRules -guid "0CCE9224-69AE-11D9-BED3-505054503030" -rules $rules + $m_file_system = CountRules -guid "0CCE921D-69AE-11D9-BED3-505054503030" -rules $rules $m_filtering_platform_connection = CountRules -guid "0CCE9226-69AE-11D9-BED3-505054503030" -rules $rules - $m_filtering_platform_packet_drop = CountRules -guid "" -rules $rules - $m_kernel_object = CountRules -guid "" -rules $rules - $m_handle_manipulation = CountRules -guid "" -rules $rules - $m_other_object_access_events = CountRules -guid "" -rules $rules - $m_registry = CountRules -guid "" -rules $rules - $m_removable_storage = CountRules -guid "" -rules $rules - $m_sam = CountRules -guid "" -rules $rules - $m_audit_policy_change = CountRules -guid "" -rules $rules - $m_authentication_policy_change = CountRules -guid "" -rules $rules - $m_authorization_policy_change = CountRules -guid "" -rules $rules - $m_filtering_platform_policy_change = CountRules -guid "" -rules $rules - $m_mpssvc_rule_level_policy_change = CountRules -guid "" -rules $rules - $m_other_policy_change_events = CountRules -guid "" -rules $rules - $m_non_sensitive_use_events = CountRules -guid "" -rules $rules - $m_sensitive_privilege_use = CountRules -guid "" -rules $rules - $m_other_system_events = CountRules -guid "" -rules $rules + $m_filtering_platform_packet_drop = CountRules -guid "0CCE9225-69AE-11D9-BED3-505054503030" -rules $rules + $m_kernel_object = CountRules -guid "0CCE921F-69AE-11D9-BED3-505054503030" -rules $rules + $m_handle_manipulation = CountRules -guid "0CCE9223-69AE-11D9-BED3-505054503030" -rules $rules + $m_other_object_access_events = CountRules -guid "0CCE9227-69AE-11D9-BED3-505054503030" -rules $rules + $m_registry = CountRules -guid "0CCE921E-69AE-11D9-BED3-505054503030" -rules $rules + $m_removable_storage = CountRules -guid "0CCE9245-69AE-11D9-BED3-505054503030" -rules $rules + $m_sam = CountRules -guid "0CCE9220-69AE-11D9-BED3-505054503030" -rules $rules + $m_audit_policy_change = CountRules -guid "0CCE922F-69AE-11D9-BED3-505054503030" -rules $rules + $m_authentication_policy_change = CountRules -guid "0CCE9230-69AE-11D9-BED3-505054503030" -rules $rules + $m_authorization_policy_change = CountRules -guid "0CCE9231-69AE-11D9-BED3-505054503030" -rules $rules + $m_filtering_platform_policy_change = CountRules -guid "0CCE9233-69AE-11D9-BED3-505054503030" -rules $rules + $m_mpssvc_rule_level_policy_change = CountRules -guid "0CCE9232-69AE-11D9-BED3-505054503030" -rules $rules + $m_other_policy_change_events = CountRules -guid "0CCE9234-69AE-11D9-BED3-505054503030" -rules $rules + $m_non_sensitive_use_events = CountRules -guid "0CCE9229-69AE-11D9-BED3-505054503030" -rules $rules + $m_sensitive_privilege_use = CountRules -guid "0CCE9228-69AE-11D9-BED3-505054503030" -rules $rules + $m_other_system_events = CountRules -guid "0CCE9214-69AE-11D9-BED3-505054503030" -rules $rules $m_security_state_change = CountRules -guid "0CCE9210-69AE-11D9-BED3-505054503030" -rules $rules - $m_security_system_extension = CountRules -guid "" -rules $rules - $m_system_integrity = CountRules -guid "" -rules $rules + $m_security_system_extension = CountRules -guid "0CCE9211-69AE-11D9-BED3-505054503030" -rules $rules + $m_system_integrity = CountRules -guid "0CCE9212-69AE-11D9-BED3-505054503030" -rules $rules $msg = @" Detailed Security category settings: