-
Notifications
You must be signed in to change notification settings - Fork 0
Security
Local/domain audit policy inspection.
1 function(s) in Public/security/.
-
Get-AuditPolicy— Report advanced audit policy subcategory settings from auditpol.exe
Report advanced audit policy subcategory settings from auditpol.exe.
Parses the advanced audit policy returned by 'auditpol.exe /get /category:* /r' (CSV) into one object per subcategory, reporting Success and Failure auditing state. It is a base building block for CIS/ANSSI compliance auditing and supports local and remote targets via Invoke-RemoteOrLocal, with optional filtering to a single category. Each Subcategory GUID is mapped to its parent Category using a static, well-known GUID map since 'auditpol /r' does not expose Category as a column.
Syntax
Get-AuditPolicy [-ComputerName <string[]>] [-Credential <System.Management.Automation.PSCredential>] [-Category <string>]Examples
Get-AuditPolicyReturns advanced audit policy subcategory settings for the local machine.
Get-AuditPolicy -Category 'Logon/Logoff'Returns only the subcategories belonging to the 'Logon/Logoff' category on the local machine.
Get-AuditPolicy -ComputerName SRV01 -Credential (Get-Credential)Returns advanced audit policy subcategory settings from SRV01 via WinRM, using the supplied credential.
'SRV01','SRV02' | Get-AuditPolicyReturns advanced audit policy subcategory settings for SRV01 and SRV02 via pipeline.
Output: PSWinOps.AuditPolicy
One object per audit subcategory, with Category, Subcategory, SubcategoryGuid, AuditSuccess, AuditFailure and the derived Setting string.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)