|
Posted by mlucasg on February 28, 2007, 2:01 pm
Please log in for more thread options
Hello everybody!
My question is: there's a way to audit or log when some user kills a
process (using KIIL utility or Windows XP's TASKKILL)?
Example: TASKKILL /S \SERVER /IM notepad.exe
I tried to enable audit policy on my Windows Server 2003 (w/ SP1), but
Event Viewer only reports that some process was finished (Security
Event ID 593).
Thanks for any help.
Marcelo Lucas Guimar=E3es
|