D
D
Dron192020-01-15 08:05:56
Windows
Dron19, 2020-01-15 08:05:56

Track the start of the windows process in the event log?

How to track the launch of the trustedinstaller process in the event log?
The goal is to lower the priority of the process execution upon the fact of its launch

Answer the question

In order to leave comments, you need to log in

1 answer(s)
A
Andrey Semenov, 2020-01-22
@EraserKhv

1. Enable audit in local policies "Computer Configuration" -> "Windows Policy" -> "Security" -> "Advanced Audit" -> "Detailed Tracking" -> "Audit Process Creation".
After that, events will appear in the Security section about starting processes, for example, No. 4688.
It remains to program the application / script that will respond to this event.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question