Merge remote-tracking branch 'refs/remotes/origin/master' into live

This commit is contained in:
LizRoss
2017-05-30 10:04:16 -07:00
3 changed files with 5 additions and 5 deletions

View File

@ -22,9 +22,9 @@ Audit Other Object Access Events allows you to monitor operations with scheduled
| Computer Type | General Success | General Failure | Stronger Success | Stronger Failure | Comments |
|-------------------|-----------------|-----------------|------------------|------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Domain Controller | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICPM DoS attack. |
| Member Server | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICPM DoS attack. |
| Workstation | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICPM DoS attack. |
| Domain Controller | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICMP DoS attack. |
| Member Server | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICMP DoS attack. |
| Workstation | Yes | Yes | Yes | Yes | We recommend Success auditing first of all because of scheduled tasks events.<br>We recommend Failure auditing to get events about possible ICMP DoS attack. |
**Events List:**

View File

@ -15,7 +15,7 @@ author: Mir0sh
- Windows Server 2016
In most circumstances, this event occurs very rarely. It is designed to be generated when an ICPM DoS attack starts or was detected.
In most circumstances, this event occurs very rarely. It is designed to be generated when an ICMP DoS attack starts or was detected.
There is no example of this event in this document.

View File

@ -15,7 +15,7 @@ author: Mir0sh
- Windows Server 2016
In most circumstances, this event occurs very rarely. It is designed to be generated when an ICPM DoS attack ended.
In most circumstances, this event occurs very rarely. It is designed to be generated when an ICMP DoS attack ended.
There is no example of this event in this document.