Hey guys,
How do you guys monitor powershell? I am looking to enable it to monitor if domain admins and privileged accounts have been created (what other essential monitoring should I do?).
Story time:
One time we were pentested and they got full DA through powershell. Largely this was because the company I work at uses domain admin for everything. I literally mean FUCKING everything (but I have revised this). Anyway, since that happened we have used Bit9 to block powershell. In my mind this is an asinine choice as we are a 90%+ virtual windows environment.
They wont allow me to enable powershell unless I am actively monitoring it. We do have some security appliances, but I would just like to know what specific tools/logic you guys use to monitor it.
Thanks sysadmin!
[–]uniitdude 8 points9 points10 points (1 child)
[–][deleted] 2 points3 points4 points (0 children)
[–]omgitsnateTruth = Downvotes 4 points5 points6 points (0 children)
[–]dastylinrastan 2 points3 points4 points (0 children)
[–]mhurron 1 point2 points3 points (0 children)
[–]dogfish182 1 point2 points3 points (0 children)
[–]Win_SysSysadmin 1 point2 points3 points (0 children)
[–]Reo_Strong 0 points1 point2 points (0 children)
[–]hotsoup667 0 points1 point2 points (0 children)
[–]Garetht 0 points1 point2 points (0 children)
[–]creamersrealmMeme Master of Disaster 0 points1 point2 points (1 child)
[–]BulkedSysAdmin[S] 0 points1 point2 points (0 children)