Vulnerability Discussion
Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises that have occurred, as well as detect attacks. Audit logs are necessary to provide a trail of evidence in case the system or network is compromised. Collecting this data is essential for analyzing the security of information assets and detecting signs of suspicious and unexpected behavior.
Enabling PowerShell Transcription will record detailed information from the processing of PowerShell commands and scripts. This can provide additional detail when malware has run on a system.Check
If the following registry value does not exist or is not configured as specified, this is a finding:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription\
Value Name: EnableTranscripting
Value Type: REG_DWORD
Value: 1
The location used for log storage must be a write-only, restricted directory (preferably a network share) that security personnel can access. The registry value setting for "Transcript output directory" is set by the GPO to "C:\ProgramData\PS_Transcript". That directory allows Read, Modify, and Delete access by standard (nonprivileged) user accounts. Either a different directory that has appropriate access permissions must be configured (see Fix text), or the permissions for the existing Transcript output directory must be configured appropriately.
If the directory used to store the PowerShell transcription log files (Transcript output directory) permits read or modify access by nonprivileged users, this is a finding.
If the output directory set by the GPO is preferred, the access permissions must be revised to ensure the PowerShell Transcription log files are accessible only to the Administrator and System accounts.
To review permissions of the output directory, enter the following commands.
Open "Command Prompt (Admin)".
[Enter "icacls" followed by the directory configured to store PowerShell Transcription logs:]
icacls C:\ProgramData\PS_Transcript
If log files currently reside in the output directory, issue the following:
icacls C:\ProgramData\PS_Transcript\*.*
The results must be displayed as below:
NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
BUILTIN\Administrators:(OI)(CI)(IO)(F)
*NT AUTHORITY\Authenticated Users:(OI)(CI)(WD,AD)
*BUILTIN\Users:(OI)(CI)(WD,AD)
*Note: The standard user accounts may differ based on the system's purpose/role and Active Directory structure.
If the directory used to store PowerShell Transcription logs is not configured to provide Full Control access to Administrative and System accounts while permitting write-only access for standard user accounts, this is a finding.Fix
Configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows PowerShell >> "Turn on PowerShell Transcription" to "Enabled".
If a centralized (versus local) Transcript output directory is preferred, configure the Transcript output directory to point to a Central Log Server or another secure location to prevent user Read, Modify, and Delete access by nonprivileged accounts.
Ensure the selected directory is write-only with Full Control access granted to Administrator and System accounts.
Enter the following registry value:
Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \SOFTWARE\Policies\Microsoft\Windows\PowerShell\Transcription
*Value Name: OutputDirectory
Value Type: REG_SZ (String Value)
* Note: "OutputDirectory" value should be: "[custom directory path (e.g., I:\UserX_PowerShellTranscripts)]"
If the folder configured (in the registry) as the Transcript output directory is not configured to provide Full Control access to Administrative and System accounts, while permitting WD, AD access for standard user accounts, issue the following commands:
Open "Command Prompt (Admin)".
1. If the directory configured to store PowerShell Transcription logs does not exist:
mkdir C:\ProgramData\PS_Transcript
2. Assign appropriate permissions to Administrators group and System account:
icacls "C:\ProgramData\PS_Transcript" /inheritance:r /grant:r "Administrators:(OI)(CI)(F)" /grant:r "SYSTEM":(OI)(CI)(F)
3. Assign appropriate permissions to user groups:
icacls "C:\ProgramData\PS_Transcript" /grant:r "Users":(OI)(CI)(WD,AD) /t /c
icacls "C:\ProgramData\PS_Transcript" /grant:r "Authenticated Users":(OI)(CI)(WD,AD) /t /c