feat: monitor admin share access via Security 5140 C$/ADMIN$ (2.0.19-SAC)

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
PTah
2026-06-04 10:14:14 +10:00
parent e3149785dc
commit 5fc5f2a9ad
4 changed files with 230 additions and 12 deletions
+1
View File
@@ -48,6 +48,7 @@ $DailyReportEnabled = 1
# --- RDS Shadow Control + WinRM inbound (Enter-PSSession), severity warning ---
# $EnableRcmShadowControlMonitoring = 1 # RCM Operational 20506/20507/20510
# $EnableWinRmInboundMonitoring = 1 # WinRM Operational 91 (+ correlate Security 4624)
# $EnableAdminShareMonitoring = 1 # Security 5140 C$/ADMIN$ (audit File Share)
# $WinRmIgnoreLocalSource = 1 # ::1, 127.0.0.1, fe80 (шум Exchange/локальный WinRM)
# $WinRmIgnoreMachineAccounts = 1 # учётки, оканчивающиеся на $
# HealthMailbox* уже в ExcludedUserPatterns скрипта