Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
namespace EventViewerX.Rules.ActiveDirectory;

public class GpoCreated : EventObjectSlim {
public string Computer;
public string Action;
public string GpoName;
public string Who;
public DateTime When;

public GpoCreated(EventObject eventObject) : base(eventObject) {
_eventObject = eventObject;
Type = "GpoCreated";
Computer = _eventObject.ComputerName;
Action = _eventObject.MessageSubject;
GpoName = _eventObject.GetValueFromDataDictionary("ObjectDN");
Who = _eventObject.GetValueFromDataDictionary("SubjectUserName", "SubjectDomainName", "\\", reverseOrder: true);
When = _eventObject.TimeCreated;
}
}

Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
namespace EventViewerX.Rules.ActiveDirectory;

public class GpoDeleted : EventObjectSlim {
public string Computer;
public string Action;
public string GpoName;
public string Who;
public DateTime When;

public GpoDeleted(EventObject eventObject) : base(eventObject) {
_eventObject = eventObject;
Type = "GpoDeleted";
Computer = _eventObject.ComputerName;
Action = _eventObject.MessageSubject;
GpoName = _eventObject.GetValueFromDataDictionary("ObjectDN");
Who = _eventObject.GetValueFromDataDictionary("SubjectUserName", "SubjectDomainName", "\\", reverseOrder: true);
When = _eventObject.TimeCreated;
}
}

Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
namespace EventViewerX.Rules.ActiveDirectory;

public class GpoModified : EventObjectSlim {
public string Computer;
public string Action;
public string GpoName;
public string AttributeLDAPDisplayName;
public string AttributeValue;
public string Who;
public DateTime When;

public GpoModified(EventObject eventObject) : base(eventObject) {
_eventObject = eventObject;
Type = "GpoModified";
Computer = _eventObject.ComputerName;
Action = _eventObject.MessageSubject;
GpoName = _eventObject.GetValueFromDataDictionary("ObjectDN");
AttributeLDAPDisplayName = _eventObject.GetValueFromDataDictionary("AttributeLDAPDisplayName");
AttributeValue = _eventObject.GetValueFromDataDictionary("AttributeValue");
Who = _eventObject.GetValueFromDataDictionary("SubjectUserName", "SubjectDomainName", "\\", reverseOrder: true);
When = _eventObject.TimeCreated;
}
}

31 changes: 31 additions & 0 deletions Sources/EventViewerX/SearchEvents.NamedEventsDetails.cs
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,19 @@ public enum NamedEvents {
/// </summary>
ADGroupPolicyLinks,

/// <summary>
/// Group Policy Object created
/// </summary>
GpoCreated,
/// <summary>
/// Group Policy Object deleted
/// </summary>
GpoDeleted,
/// <summary>
/// Group Policy Object modified
/// </summary>
GpoModified,

/// <summary>
/// Summary of LDAP binding activity
/// </summary>
Expand Down Expand Up @@ -165,6 +178,9 @@ public partial class SearchEvents : Settings {
{ NamedEvents.ADGroupPolicyChanges, ([5136, 5137, 5141], "Security")},
{ NamedEvents.ADGroupPolicyEdits, ([5136, 5137, 5141], "Security")},
{ NamedEvents.ADGroupPolicyLinks, ([5136, 5137, 5141], "Security")},
{ NamedEvents.GpoCreated, (new List<int> { 5137 }, "Security") },
{ NamedEvents.GpoDeleted, (new List<int> { 5141 }, "Security") },
{ NamedEvents.GpoModified, (new List<int> { 5136 }, "Security") },
// user based events
{ NamedEvents.ADUserCreateChange, ([4720, 4738], "Security") },
{ NamedEvents.ADUserStatus, ([4722, 4725, 4723, 4724, 4726], "Security") },
Expand Down Expand Up @@ -321,6 +337,21 @@ private static EventObjectSlim BuildTargetEvents(EventObject eventObject, List<N
return new ADGroupPolicyEdits(eventObject);
}
break;
case NamedEvents.GpoCreated:
if (objectClass == "groupPolicyContainer") {
return new GpoCreated(eventObject);
}
break;
case NamedEvents.GpoDeleted:
if (objectClass == "groupPolicyContainer") {
return new GpoDeleted(eventObject);
}
break;
case NamedEvents.GpoModified:
if (objectClass == "groupPolicyContainer") {
return new GpoModified(eventObject);
}
break;

default:
throw new ArgumentException($"You forgot to add NamedEvents value properly: {typeEvents}");
Expand Down
Loading