docs: note Exchange WinRM strict mode in agent integration
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -208,6 +208,8 @@ Idempotency-Key: 550e8400-e29b-41d4-a716-446655440000
|
||||
**Переключатели в `login_monitor.settings.ps1` (≥ 1.2.23-SAC):** `$EnableRcmShadowControlMonitoring`, `$EnableWinRmInboundMonitoring`, `$EnableAdminShareMonitoring` (по умолчанию `1`; Security **5140**, audit File Share). **`$GetInventory`** (по умолчанию `$true`) — опрос железа/ПО для SAC. Подавление: `ignore.lst` с префиксами `shadow:`, `winrm:`, `smb:` / `5140:`.
|
||||
|
||||
**Exchange (RDP ≥ 2.0.23-SAC):** на почтовом сервере `$WinRmExchangeStrictMode = 1` — WinRM **91** без user в EventData не уходит в SAC; корреляция **4624** только при `LogonProcess WinRM` (отсекает ложные связки с Outlook/LT3).
|
||||
|
||||
---
|
||||
|
||||
## 3.3. Человекочитаемое имя хоста (`host.display_name`)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user