Custom Event Channel Permissions | |
Data collected on: 12/4/2019 5:31:16 AM |
Domain | windomain.local |
Owner | WINDOMAIN\vagrant |
Created | 12/4/2019 4:33:08 AM |
Modified | 12/4/2019 5:30:34 AM |
User Revisions | 1 (AD), 1 (SYSVOL) |
Computer Revisions | 7 (AD), 7 (SYSVOL) |
Unique ID | {3869352D-95F3-4FB0-BCDA-40191D897625} |
GPO Status | Enabled |
Location | Enforced | Link Status | Path |
---|---|---|---|
Domain Controllers | Yes | Enabled | windomain.local/Domain Controllers |
Servers | Yes | Enabled | windomain.local/Servers |
Workstations | Yes | Enabled | windomain.local/Workstations |
Name |
---|
NT AUTHORITY\Authenticated Users |
Name | Allowed Permissions | Inherited |
---|---|---|
NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
WINDOMAIN\Domain Admins | Edit settings, delete, modify security | No |
WINDOMAIN\Enterprise Admins | Edit settings, delete, modify security | No |
WINDOMAIN\vagrant | Edit settings, delete, modify security | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DNSServer/Audit |
Value name | ChannelAccess |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0x2;;;S-1-15-2-1)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)(A;;0x1;;;S-1-5-20) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBClient/Operational |
Value name | ChannelAccess |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0x5;;;BA)(A;;0x1;;;S-1-5-20)(A;;0x1;;;S-1-5-32-573) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Audit |
Value name | ChannelAccess |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0x5;;;BA)(A;;0x1;;;S-1-5-20)(A;;0x1;;;S-1-5-32-573) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SYSTEM\CurrentControlSet\Services\EventLog\DNS Server |
Value name | CustomSD |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x5;;;SO)(A;;0x1;;;IU)(A;;0x1;;;SU)(A;;0x1;;;S-1-5-3)(A;;0x2;;;LS)(A;;0x2;;;NS)(A;;0x2;;;S-1-5-33)(A;;0x1;;;S-1-5-20)(A;;0x1;;;S-1-5-32-573) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SYSTEM\CurrentControlSet\Services\EventLog\Security |
Value name | CustomSD |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0xf0005;;;SY)(A;;0x5;;;BA)(A;;0x1;;;S-1-5-32-573)(A;;0x1;;;S-1-5-20) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |
Action | Update |
Hive | HKEY_LOCAL_MACHINE |
Key path | SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Sysmon/Operational |
Value name | ChannelAccess |
Value type | REG_SZ |
Value data | O:BAG:SYD:(A;;0x5;;;BA)(A;;0x1;;;S-1-5-20)(A;;0x1;;;S-1-5-32-573) |
Stop processing items on this extension if an error occurs on this item | No |
Remove this item when it is no longer applied | No |
Apply once and do not reapply | No |