Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: How to capture failed 'Run as Administrator' events on a Windows domain?

$
0
0

IIRC, it won't auth against the domain controllers, because the privilege escalation is attempted locally.  When a 'run as administrator' request is generated, windows checks to see if the user is in the local administrator group, or a group which is by default granted administrator rights (such as Domain Admins).  This doesn't have to go out to a domain controller, since the escalation would be done locally.  


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>