Activity Auditing
Enabling Auditing for WEF Operations¶
To audit WEF operations, configure Windows Audit Policies to track events related to event log management and forwarding. These policies are managed via Group Policy or Local Security Policy:
-
Audit Event Log Management
Enable auditing for events related to event log creation, deletion, and modification. This captures actions like configuring event subscriptions or modifying the Event Log service.
Command to enable via PowerShell:
-
Audit Event Creation and Deletion
Track when events are added to or removed from the event log. This helps detect unauthorized modifications to event data.
Group Policy Location:
Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Audit Event Creation and Deletion -
Audit Event Forwarding
While Windows does not provide a direct policy for WEF-specific auditing, the Security log on the collector server can be configured to capture events related to event forwarding (e.g., successful or failed event ingestion). Note that WEF operations are indirectly monitored via Security log events, which may include standard event IDs like 4663 or 4656.
Monitoring Security-Related Events on the Collector¶
The collector server must log events that indicate successful or failed event forwarding operations. Use the Security log to monitor these activities:
- Event IDs to Monitor
- Event ID 4663: A user attempted to access an event log. This may indicate unauthorized access to event data.
-
Event ID 4656: A user was logged on to the system, which may correlate with event forwarding activity.
Note: Event ID 10000000000 is not a standard Windows event ID. Use verified IDs like 4663 or 4656 for monitoring, or define custom event IDs as needed. -
Configuring the Security Log
Ensure the Security log is enabled and configured to retain sufficient historical data. Adjust log size and retention via: -
Event Viewer > Windows Logs > Security > Properties > Retention Settings
-
Using PowerShell to Query Logs
Filter the Security log for WEF-related events usingGet-WinEvent:
Real-Time Monitoring and Alerts¶
Set up real-time monitoring for critical events using Event Subscriptions or SIEM integration:
- Event Subscriptions
Create a subscription in Event Viewer to forward specific events to a centralized log server or monitoring tool.
Steps: - Open Event Viewer > Action > Event Subscriptions.
-
Configure a subscription to filter events (e.g., Event ID 4663) and forward them to a remote server.
-
SIEM Integration
Forward Security log events to a Security Information and Event Management (SIEM) system (e.g., Microsoft Sentinel, Splunk) for centralized analysis and alerting.
Key takeaways¶
- Enable audit policies for Event Log Management and Event Creation/Deletion to track WEF-related activities.
- Monitor the Security log on the collector server for events like 4663 and 4656 to detect unauthorized access or failures.
- Use PowerShell to query and filter event logs for targeted analysis.
- Integrate with SIEM tools for real-time monitoring and alerting on suspicious event forwarding behavior.