Security Monitoring: Include Command Line for Process Auditing Setting on DCs

Security.Monitoring.IncludeCommandLineProcessCreationonDCs (UnitMonitor)

This monitor will look at the registry key that needs to be set to include command line in 4688 events

Element properties:

TargetMicrosoft.Windows.Server.DC.Computer
Parent MonitorSystem.Health.ConfigurationState
CategoryAvailabilityHealth
EnabledTrue
Alert GenerateFalse
Alert Auto ResolveTrue
Monitor TypeSecurityMonitoringMP.CommandLineAuditSetting
RemotableTrue
AccessibilityInternal
RunAsDefault

Source Code:

<UnitMonitor ID="Security.Monitoring.IncludeCommandLineProcessCreationonDCs" Accessibility="Internal" Enabled="true" Target="Windows!Microsoft.Windows.Server.DC.Computer" ParentMonitorID="Health!System.Health.ConfigurationState" Remotable="true" Priority="Normal" TypeID="SecurityMonitoringMP.CommandLineAuditSetting" ConfirmDelivery="false">
<Category>AvailabilityHealth</Category>
<OperationalStates>
<OperationalState ID="RegValueBad" MonitorTypeStateID="RegValueBad" HealthState="Warning"/>
<OperationalState ID="RegValueGood" MonitorTypeStateID="RegValueGood" HealthState="Success"/>
</OperationalStates>
<Configuration>
<ComputerName>$Target/Property[Type="Windows!Microsoft.Windows.Computer"]/NetworkName$</ComputerName>
</Configuration>
</UnitMonitor>