yesterday Microsoft published the security advisory 3004375
<https://technet.microsoft.
announcing an update which enables Windows 7 and newer to log
the command lines used to start processes to the event log.
If you want to have this functionality on older versions of
Windows too see <http://home.arcor.de/
(but notice the license terms).
Limitation: command lines of processes that dont load USER32.DLL
are not logged. Fortunately almost all Win32 applications but
load USER32.DLL
JFTR: APPINIT.DLL works since 20 years.
regards
Komentarų nėra:
Rašyti komentarą