Module 16: Active Directory Persistence
Keeping Domain Access
Domain Group Memberships
Group Name
Description
Scope Name
Definition
PS C:\Windows\system32> auditpol /get /category:"Account Management"
System audit policy
Category/Subcategory Setting
Account Management
Computer Account Management Success
Security Group Management Success
Distribution Group Management No Auditing
Application Group Management No Auditing
Other Account Management Events No Auditing
User Account Management SuccessEvent ID
Description
Domain User Modifications
Golden Tickets
Last updated