
Active Directoryã®ç£èŠã«é¢ããäžé£ã®åºçç©ãéå§ããŸãã
ãããã®èšäºã§ã¯ãæãåºæ¬çãªåé¡ãšãããã解決ããæ¹æ³ã玹ä»ããŸãã ãããã®ããŒã¿ã«åºã¥ããŠãæ©èœã¯å¿
èŠãªèŠä»¶ã«ç°¡åã«æ¡åŒµã§ããŸãã
çŸåšãPowershellã¯ãWindows Server 2003 R2ããã³Windows XP SP3以éã®ãã¹ãŠã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§äœ¿çšã§ããããšãåæãšããŠããŸãã ãã®èšäºã¯åœ¹ã«ç«ã€å©ãã«ãªããšæããŸãããªããªãã 管çè
ãè¿œå ã®è³éãå°å
¥ããå¿
èŠã¯ãããŸããã åºæ¬çã«å®æçãªæ段ã«ããç£èŠã
ããã§ã¯å§ããŸãããã
Active Directoryã®ç£èŠ
ãã¹ãŠã®ITããã°ã³ãã¥ããã£ã§ADã¢ãã¿ãªã³ã°ã«é¢ããå€ãã®èšäºãèŠã€ããããšãã§ããŸããã...ãããããããã®90ïŒ
以äžã¯ãµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ã®äœ¿çšã«å°å¿µããŠããããã®å€ãã¯ãããšãå€ãã§ã¯ãªããŠãããã¹ãŠã®äŒæ¥ãåãã§æäŸããããã§ã¯ãªãäžå®ã®éé¡ãããããŸãã ãããããèšäºæ°ã®èšé²ä¿æè
ã¯NetWrix Corporationã®è£œåã§ãã ãã¡ãã¡ã§ãITå°é家ããã®ããã°ã©ã ã®çŽ æŽãããç¹åŸŽãæããŸãã ãããããªããšçœªãé ãã®ãã圌ã¯ãã®ããã°ã©ã ããã¢ã¢ãŒãã§äœ¿çšããŸããã æ£çŽãªãšãããç§ã¯ããã奜ãã§ããã¹ãŠãã·ã³ãã«ã§æé ãªäŸ¡æ Œã§ããã圌ãã¯ããã®ããã«ãéãäžããŸãããã€ãŸãããã¢æéã®çµãããŸã§ã«ADã¯åã³ãéããç®ãªãã§æŸçœ®ãããããšãæå³ããŸã åºæ¬çã«ç§ã«åããªãã£ããã®ã
å°ããªããªã¢ãŒ
ãåãã®ãšããããã¹ãŠã®ã¹ãã©ã€ãã®Windowsã®ã»ãã¥ãªãã£ããªã·ãŒã«ã¯ãã€ãã³ããç£æ»ããæ©èœããããŸãã ãã®ç£æ»ã«ããããžã£ãŒãã«ãã»ãã¥ãªãã£ãã®ã€ãã³ããã°ã«ãšã³ããªãèªåçã«çæã§ããŸãã ç£æ»ã¯ããã°ã€ã³ããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãã¢ã«ãŠã³ã管çãããªã·ãŒã®å€æŽãªã©ãããã€ãã®ã¿ã€ãã®ã€ãã³ãã«å¯ŸããŠå®æœã§ããŸãã 9çš®é¡ã®ã€ãã³ãã®ã¿ã ããã¯åºæ¬çãªç£æ»ã§ãã Windows 7ããã³Windows Server 2008R2以éãç£æ»ã€ãã³ãã®æ°ã¯53ã«å¢å ããŸãããããã«ãããå¿
èŠãªã€ãã³ãã®ã¿ããã詳现ã«ç£æ»ã§ããŸãã é«åºŠãªç£æ»ããªã·ãŒã®è©³çŽ°ã«ã€ããŠã¯ã
ãã¡ããã芧ãã ãã ã
ãããããåç¥ã®ããã«ãå°ãªããšãäžåºŠã¯EventLogã®ã»ãã¥ãªãã£ã»ã¯ã·ã§ã³ã調ã¹ãŠããã«äœããèŠã€ããŸãã-äžå¯èœã§ã¯ãªãã«ããŠããå°ãªããšãéåžžã«å°é£ã§ãã
ã¢ã€ãã¢...
ãããŠãããã§ã¢ã€ãã¢ãçãŸããŸãã... Windowsã¯EventLogã«ã€ãã³ããã°ãšã³ããªãäœæã§ãããããçè«çã«ã¯ãã®æ
å ±ãååŸã§ããŸãã 1ã€ã®ããããã...ãã®ãã°ã¯å€§ããããŠç®çã®ã€ãã³ããæåã§æ€çŽ¢ã§ãããæéã®çµéãšãšãã«ãã°ã®ãµã€ãºãå¶éããªããšãæ°åã®ã¬ãã€ãã«æé·ããå¯èœæ§ããããŸãã ãã®ãããEventLogã§é©åãªæ
å ±ãèªåçã«èŠã€ããåé¡ã解決ããå¿
èŠããããŸãã 幞ããªããšã«ãåã¿ã€ãã®ã€ãã³ãïŒããšãã°ããŠãŒã¶ãŒã¢ã«ãŠã³ãã®äœæïŒã«ã¯ããããèŠã€ããããã®ç¬èªã®IDããããŸãã
ãããã£ãŠãæ€çŽ¢ã®åé¡ã解決ããã«ã¯ããžã£ãŒãã«ã§ãã®ã€ãã³ããèŠã€ããã ãã§ãã
Powershell 2.0ã«ã¯ãEventLog-
Get-WinEventãæäœããããã®ç¹å¥ãªã³ãã³ãã¬ããããããŸãã
ãã®ã³ãã³ãã¬ããã䜿çšãããšãEventLogã§ç¹å®ã®ã¬ã³ãŒããååŸã§ããŸãã
å®è£
ã°ã«ãŒãããªã·ãŒã§ããã¡ã€ã³ã³ã³ãããŒã©ãŒã«é©çšããŠã¢ã«ãŠã³ãã«é¢é£ããã€ãã³ããç£æ»ããããšã瀺ãããšããŸãã
次ã«ãADã§éãããã¢ã«ãŠã³ãã§ã®ã¢ã¯ã·ã§ã³ã¯ãç¹å®ã®èå¥åã§EventLogã«ãšã³ããªãäœæããã€ãã³ããçæããŸãã ããšãã°ããã®æäœãå®è¡ããããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ãã¡ã€ã³ã«ã³ã³ãã¥ãŒã¿ãŒãè¿œå ããããšãã»ãã¥ãªãã£ãã°ã®EventLogã«
ID = 4741ã®ãšã³ããªãŒãããããã€ã誰ãã©ã®ã³ã³ãã¥ãŒã¿ãŒããã¡ã€ã³ã«è¿œå ãããã瀺ããŸãã
æå®ãããèå¥åãæã€æåŸã®ã€ãã³ããååŸããã«ã¯ãPowershellã¯ãšãªã䜿çšããŸãã
Get-WinEvent -FilterHashtable @{LogName=âSecurityâ;ID=4741}
ããããæ®å¿µãªãããåºå圢åŒã¯æé«ã®ãã®ãæ®ãããã®ã§ãã ã»ãã¥ãªãã£èå¥åãäžé£ã®å±æ§ãªã©ãå€ãã®è¿œå æ
å ±ã
TimeCreated : 12.07.2012 14:02:19 ProviderName : Microsoft-Windows-Security-Auditing Id : 4741 Message : . : : S-1-5-21-451469775-2953165952-2320738315-500 : administrator : DOMAIN : 0xb3acf : : S-1-5-21-451469775-2953165952-2320738315-2979 : TEST$ : DOMAIN : SAM: TEST$ : - : - : - : - : - : - : - : <> : <> : 515 : - UAC: 0x0 UAC: 0x85 : " " - " " - : - SID: - : < > DNS- : - : - : Privileges -
æãåºæ¬çãªæ
å ±ãæéãäœæè
ãã³ã³ãã¥ãŒã¿ãŒåã«èå³ããããŸãã ãããè¡ãã«ã¯ããªã¯ãšã¹ãããå°ãã埮調æŽããŸãã
Get-WinEvent -FilterHashtable @{LogName=âSecurityâ;ID=4741} | Select TimeCreated,@{n=ââ;e={([xml]$_.ToXml()).Event.EventData.Data | ? {$_.Name -eq âSubjectUserNameâ} |%{$_.'#text'}}},@{n=â â;e={([xml]$_.ToXml()).Event.EventData.Data | ? {$_.Name -eq âSamAccountNameâ}| %{$_.'#text'}}}
ãã®çµæããã®ã¯ãšãªã®çµæã¯ããã§ã«ç®ã«äŸ¿å©ãªæ
å ±ã«ãªããŸãã
TimeCreated : 12.07.2012 14:02:19 : administrator : TEST$
ãã®èŠæ±ã¯ãEventLogã®ã€ãã³ããXMLãªããžã§ã¯ããšèŠãªããŸãã ãããŠãå¿
èŠãªå€ãã€ãŸã æéïŒTimeCreatedïŒããªãã¬ãŒã¿ãŒãã³ã³ãã¥ãŒã¿ãŒåã
ã芧ã®ãšãããã³ãŒãã¯éåžžã«èªã¿ããããããŸããã ã€ãã³ããåŠçã§ããããã«ãããããWindows Eventlogã¯åã€ãã³ããéšåæååã«è§£æã§ããç¹å¥ãª.Netã¯ã©ã¹ãæäŸããŸããPowershellã¯å®éã«ã¯.NETã§ããããããããã®æ©èœãå©çšã§ããŸãã
ããšãã°ã次ã®ã³ãŒãã¯ã€ãã³ããéšåæååã«è§£æããŸãã
Get-Eventlog Security -InstanceId 4768| Select TimeGenerated,ReplacementStrings | % { New-Object PSObject -Property @{ UserName = $_.ReplacementStrings[0] IPAddress = $_.ReplacementStrings[9] Date = $_.TimeGenerated } }
ãã®çµæã次ã®ãããªçµæãåŸãããŸãã
Date : 12.07.2012 14:02:19 Username : administrator IPAddress : 10.10.10.1
ãã®ã³ãŒãã¯èªã¿ããããªã£ãŠããŸãã
ãªã¯ãšã¹ããããã«è©³ããèããŠã¿ãŸãããã
ãªãã·ã§ã³1ïŒèŠæ±ã¯ã€ãã³ããXLMãšèŠãªããŸãïŒïŒEventLogã®ãšã³ããªãéããšãäžè¬ãšè©³çŽ°ã®2ã€ã®ããã¯ããŒã¯ã衚瀺ãããŸãã
ã詳现ãã¿ãã«ç§»åããŠè¡šç€ºã¢ãŒããXMLã¢ãŒãããéžæãããšãåãã€ãã³ãæ§é ãXML圢åŒã§è¡šç€ºãããŸãã
ãã®ã€ãã³ããXMLãšããŠè§£æããããããå¿
èŠãªå€ãéžæããŸããEvent.EventData.Dataã»ã¯ã·ã§ã³ã§ãSubjectUserNameãšããååã®ãã©ã¡ãŒã¿ãŒã¯ã³ã³ãã¥ãŒã¿ãŒãäœæãããŠãŒã¶ãŒã®ååã§ãSamAccountNameãšããååã®ãã©ã¡ãŒã¿ãŒã¯äœæãããã³ã³ãã¥ãŒã¿ãŒã®ååã§ãã
ãªãã·ã§ã³2ïŒéšåæååã®äžã§è§£æïŒïŒåæ§ã«ãã€ãã³ããXMLãšããŠéããã»ã¯ã·ã§ã³Event.EventData.DataãèŠã€ããŠãè¡ãã«ãŠã³ãããŸãïŒ0ããéå§ïŒ-ãããã¯ãµãã¹ããªã³ã°ã®ã€ã³ããã¯ã¹ã§ãã å¿
èŠãªå€ãæã€è¡ãèŠã€ãããããäœè¡ã«ããããæ€èšããŸãã
ããã§ããã®æ
å ±ãã©ããã«è¡šç€ºããå¿
èŠããããŸããã³ã³ãœãŒã«ã«ä¿åããªãã§ãã ããã
ããã«è¯ãããšã«ãããã管çè
ã«ã¡ãŒã«ãªã©ã§éä¿¡ãããå Žåã
Powershell 2.0ã«ã¯ãã³ã³ãœãŒã«ã¹ã¿ã€ã«ã®SMTPã»ãã·ã§ã³ãšé»åã¡ãŒã«ã®éä¿¡æ©èœããããŸãã
Send-MailMessage-ãã®æ©èœãå®è¡ããã³ãã³ãã¬ããã
ã¡ãã»ãŒãžãéä¿¡ããã«ã¯ãSMTPãµãŒããŒãéä¿¡è
ã¢ãã¬ã¹ãåä¿¡è
ã¢ãã¬ã¹ãã¡ãã»ãŒãžæ¬æãã¡ãã»ãŒãžã®ä»¶åããŠãŒã¶ãŒåããã¹ã¯ãŒããæå®ããå¿
èŠããããŸãã
ãã®çµæãID = 4741ã®èå¥åã§æåŸã®ã€ãã³ããæ€çŽ¢ãã管çè
ã«ã¡ãŒã«ã§æ
å ±ãéä¿¡ãã次ã®ãªã¯ãšã¹ããååŸããŸãã
# $Theme = â â # , . $Subject = â â # $Server = âmail.domain.ruâ # SMTP $From = âaudit@domain.ruâ # $To = âadmin@domain.ruâ # $pass = ConvertTo-SecureString âPASSWORDâ -AsPlainText -Force # $cred = New-Object System.Management.Automation.PSCredential(âAUDITâ , $pass) # $encoding = [System.Text.Encoding]::UTF8 # UTF8 # . ID. Body. $Body=Get-WinEvent -FilterHashtable @{LogName=âSecurityâ;ID=4741} | Select TimeCreated,@{n=ââ;e={([xml]$_.ToXml()).Event.EventData.Data | ? {$_.Name -eq âSubjectUserNameâ} |%{$_.'#text'}}},@{n=â â;e={([xml]$_.ToXml()).Event.EventData.Data | ? {$_.Name -eq âSamAccountNameâ}| %{$_.'#text'}}} | select-object -first 1 # . Send-MailMessage -From $From -To $To -SmtpServer $server -Body â$Theme `n$BodyMâ -Subject $Subject -Credential $cred -Encoding $encoding
ãŸãšã
ãã®ã¹ã¯ãªããããps1æ¡åŒµåã®ä»ãããã¡ã€ã«ã«ä¿åããŸããããšãã°ãDïŒ\ Scripts \ ADCompAdd.ps1
Powershellã³ã³ãœãŒã«ãéããŸãã
次ã®ã³ãã³ããå
¥åããŸãïŒ
Set-ExecutionPolicy UnrestrictedãYããæŒããŠå
¥åããŸãã ãããã£ãŠããµãŒããŒã§ã®Powershellã¹ã¯ãªããã®å®è¡ãèš±å¯ããŸãã
ã¹ã¯ãªãããã³ã³ãœãŒã«ã«ãã©ãã°ãïŒãã©ãã°ã¢ã³ãããããïŒãEnterããŒãæŒããŸãã ã¹ã¯ãªããããšã©ãŒãªãã§å®è¡ãããããšã確èªããŸãïŒã€ãŸããã³ã³ãœãŒã«ã«èµ€ãããã¹ãããã¯ã¹ã衚瀺ãããªãã£ãïŒã å¿
èŠãªããŒã¿ãå«ãæ°ããã¡ãã»ãŒãžããªããã¡ãŒã«ã確èªããŸãã
ã€ãã³ããçºçããç¬éã«äœããã®åœ¢ã§ãã®ã¹ã¯ãªãããå®è¡ããããšã ããæ®ã£ãŠããŸãã
次ã«ããã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ãã圹ç«ã¡ãŸãã
ã¹ã±ãžã¥ãŒã©ã«ã¯ãEventLogã®ç¹å®ã®ã€ãã³ãã«å¿çããæ©èœããããŸãã
ã»ãã¥ãªãã£ãã°ã«è¡šç€ºãããçªå·4741ã®äžã®ã€ãã³ãã«å¿çããããšãããªã¬ãŒã§ç€ºãã¿ã¹ã¯ãäœæããŸãã
ãŸãããã®ã¹ã¯ãªãããå®è¡ããå¿
èŠãããããšã瀺ããŠããŸãã ãããè¡ãã«ã¯ããã¢ã¯ã·ã§ã³ãã§ããã°ã©ã ãå®è¡ããããšãæå®ãããããã°ã©ã ãŸãã¯ã¹ã¯ãªããããã£ãŒã«ãã«ã
powershell ããšèšè¿°ããŸãã ãåŒæ°ã®è¿œå ïŒãªãã·ã§ã³ïŒããã£ãŒã«ãã«ã
-nologo -noprofile -Fileããšå
¥åããŸãDïŒ\ Scripts \ ADCompAdd.ps1â³ â
次ã«ãäœæãããæ§é ãã©ã®ããã«æ©èœãããããã¹ãããŸãã ADã®ã©ã®éšéã«ããã¹ãã³ã³ãã¥ãŒã¿ãŒãäœæããŸãã ã¡ãŒã«ã§ã¡ãã»ãŒãžã確èªããŸãã
ã¹ã¯ãªããã¯å®å
šã«å®å
šã§ã¯ãããŸãã ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããã¯ãªã¢ããã¹ãã§å«ãŸããŠããããããã®ã¹ã¯ãªããã䜿çšããå Žåã¯ãã¢ã«ãŠã³ãã䜿çšããŠæå°éã®æš©éã§ã¡ãã»ãŒãžãéä¿¡ããããšã匷ããå§ãããŸãã
ç§ã®æž¬å®ã«ãããšãã€ãã³ãã«å¯Ÿããåå¿æéã¯1ç§ã§ãã ã€ãŸã äœæããæçŽã®åé ãŸã§1ç§ãçµéããŸãã ãã¡ãããã€ã³ã¿ãŒãããã®ã©ããã§ã¯ãªããããŒã«ã«ã¡ãŒã«ãµãŒããŒã䜿çšããŠããå Žåã«éããŸãã é
延ãããå ŽåããããŸãã ããããå
šäœçã«ã¯é«ããããŸããã
ãã®çµæããã®ã¹ã¯ãªãããåºç€ãšããŠãã€ãã³ãå
ã®ã€ãã³ãããååŸããå¿
èŠãããã€ãã³ãçªå·ãšããŒã¿ãå€æŽãããšãADã®ã¢ã«ãŠã³ãã§ã®ãã¹ãŠã®æäœãç£èŠã§ããŸãïŒcreate-deleteãdisable-enableãlock-unlockããAdd to groups andäŸå€ãšãã äžè¬ã«ãWindowsãç£æ»ã§ããã€ãã³ãç£èŠã ãªã¯ãšã¹ãå
ã®XMLãã£ã«ã¿ãŒãå€æŽããã ãã§ãããããè¡ãã«ã¯ãXMLã¢ãŒãã§å¿
èŠãªã€ãã³ãã確èªããå¿
èŠãªå€ãéžæããŠããªã¯ãšã¹ããã£ã«ã¿ãŒã«å
¥åããŸãã
PSïŒ
Windows Server 2008R2ã®äŸ¿å©ãªã€ãã³ãèå¥åã次ã«ç€ºããŸãã
ID = 4741ãã¡ã€ã³ã§ã®ã³ã³ãã¥ãŒã¿ãŒã®äœæ
ID = 4743ãã¡ã€ã³ããã³ã³ãã¥ãŒã¿ãŒãåé€ãã
ID = 4728ã»ãã¥ãªãã£ã°ã«ãŒããžã®è¿œå
ID = 4729ã»ãã¥ãªãã£ã°ã«ãŒãããåé€ããŠããŸã
ID = 4720ãŠãŒã¶ãŒäœæ
ID = 4726ãŠãŒã¶ãŒã®åé€
ID = 4740ã¢ã«ãŠã³ãããã¯ã¢ãŠã
ID = 4767ã¢ã«ãŠã³ãã®ããã¯è§£é€
ID = 4722ã¢ã«ãŠã³ããæå¹ã«ãã
ID = 4725ã¢ã«ãŠã³ãã®åæ