| NoxturnalFileAccess | |
| Data collected on: 12.12.2017 13:35:01 | |
| Domain | nox.local |
| Owner | NOX\Domain Admins |
| Created | 24.11.2017 14:21:46 |
| Modified | 24.11.2017 14:21:48 |
| User Revisions | 0 (AD), 0 (sysvol) |
| Computer Revisions | 33 (AD), 33 (sysvol) |
| Unique ID | {0D263DEE-CB99-4361-8A00-99C0FA4EB538} |
| GPO Status | Enabled |
| Location | Enforced | Link Status | Path |
|---|---|---|---|
| File Servers | No | Enabled | nox.local/Nox Lab/File Servers |
| Name |
|---|
| NT AUTHORITY\Authenticated Users |
| Name | Allowed Permissions | Inherited |
|---|---|---|
| NOX\Domain Admins | Edit settings, delete, modify security | No |
| NOX\Enterprise Admins | Edit settings, delete, modify security | No |
| NT AUTHORITY\Authenticated Users | Read (from Security Filtering) | No |
| NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS | Read | No |
| NT AUTHORITY\SYSTEM | Edit settings, delete, modify security | No |
| Policy | Setting |
|---|---|
| Audit: Shut down system immediately if unable to log security audits | Disabled |
| Policy | Setting |
|---|---|
| Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings | Enabled |
| Policy | Setting |
|---|---|
| Audit Credential Validation | Success, Failure |
| Audit Kerberos Authentication Service | No Auditing |
| Audit Kerberos Service Ticket Operations | No Auditing |
| Audit Other Account Logon Events | No Auditing |
| Policy | Setting |
|---|---|
| Audit Application Group Management | No Auditing |
| Audit Computer Account Management | No Auditing |
| Audit Distribution Group Management | No Auditing |
| Audit Other Account Management Events | No Auditing |
| Audit Security Group Management | No Auditing |
| Audit User Account Management | No Auditing |
| Policy | Setting |
|---|---|
| Audit DPAPI Activity | No Auditing |
| Audit Process Creation | Success |
| Audit Process Termination | No Auditing |
| Audit RPC Events | No Auditing |
| Policy | Setting |
|---|---|
| Audit Detailed Directory Service Replication | No Auditing |
| Audit Directory Service Access | No Auditing |
| Audit Directory Service Changes | No Auditing |
| Audit Directory Service Replication | No Auditing |
| Policy | Setting |
|---|---|
| Audit Account Lockout | No Auditing |
| Audit IPsec Extended Mode | No Auditing |
| Audit IPsec Main Mode | No Auditing |
| Audit IPsec Quick Mode | No Auditing |
| Audit Logoff | Success |
| Audit Logon | Success, Failure |
| Audit Network Policy Server | No Auditing |
| Audit Other Logon/Logoff Events | No Auditing |
| Audit Special Logon | Success |
| Policy | Setting |
|---|---|
| Audit Application Generated | No Auditing |
| Audit Certification Services | No Auditing |
| Audit Detailed File Share | No Auditing |
| Audit File Share | No Auditing |
| Audit File System | Success |
| Audit Filtering Platform Connection | No Auditing |
| Audit Filtering Platform Packet Drop | No Auditing |
| Audit Handle Manipulation | No Auditing |
| Audit Kernel Object | No Auditing |
| Audit Other Object Access Events | No Auditing |
| Audit Registry | No Auditing |
| Audit SAM | No Auditing |
| Policy | Setting |
|---|---|
| Audit Audit Policy Change | No Auditing |
| Audit Authentication Policy Change | Success |
| Audit Authorization Policy Change | No Auditing |
| Audit Filtering Platform Policy Change | No Auditing |
| Audit MPSSVC Rule-Level Policy Change | No Auditing |
| Audit Other Policy Change Events | No Auditing |
| Policy | Setting |
|---|---|
| Audit Non Sensitive Privilege Use | No Auditing |
| Audit Other Privilege Use Events | No Auditing |
| Audit Sensitive Privilege Use | Success, Failure |
| Policy | Setting |
|---|---|
| Audit IPsec Driver | No Auditing |
| Audit Other System Events | No Auditing |
| Audit Security State Change | Success, Failure |
| Audit Security System Extension | Success, Failure |
| Audit System Integrity | Success, Failure |