vbs AD日志開啟腳本nableKerbLog的腳本
更新時(shí)間:2008年06月16日 19:41:27 作者:
AD日志開啟腳本
Dim wsObj
Set wsObj = CreateObject("Wscript.Shell")
' Add the LogLevel Value to Kerberos Key in Registry.
On Error Resume Next
WScript.Echo "Enabling Kerberos Logging..."
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\1 Knowledge Consistency Checker",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\2 Security Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\3 ExDS Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\4 MAPI Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\5 Replication Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\6 Garbage Collection",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\7 Internal Configuration",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\8 Directory Access",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\9 Internal Processing",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\10 Performance Counters",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\11 Initialization/Termination",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\12 Service Control",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\13 Name Resolution",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\14 Backup",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\15 Field Engineering",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\16 LDAP Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\17 Setup",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\18 Global Catalog",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\19 Inter-site Messaging",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\20 Group Caching",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\21 Linked-Value Replication",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\22 DS RPC Client",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\23 DS RPC Server",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\24 DS Schema",3,"REG_DWORD"
Set wsObj = Nothing
WScript.Echo "-=[Complete!]=-"
Set wsObj = CreateObject("Wscript.Shell")
' Add the LogLevel Value to Kerberos Key in Registry.
On Error Resume Next
WScript.Echo "Enabling Kerberos Logging..."
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\1 Knowledge Consistency Checker",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\2 Security Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\3 ExDS Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\4 MAPI Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\5 Replication Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\6 Garbage Collection",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\7 Internal Configuration",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\8 Directory Access",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\9 Internal Processing",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\10 Performance Counters",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\11 Initialization/Termination",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\12 Service Control",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\13 Name Resolution",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\14 Backup",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\15 Field Engineering",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\16 LDAP Interface Events",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\17 Setup",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\18 Global Catalog",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\19 Inter-site Messaging",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\20 Group Caching",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\21 Linked-Value Replication",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\22 DS RPC Client",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\23 DS RPC Server",3,"REG_DWORD"
wsObj.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\24 DS Schema",3,"REG_DWORD"
Set wsObj = Nothing
WScript.Echo "-=[Complete!]=-"
相關(guān)文章
ie7 0day當(dāng)中的shellcode的escape+xor21加密
shellcode的escape+xor21加密2008-12-12
math.vbs 自然數(shù)n的n次方的的和或積的級(jí)數(shù)
通項(xiàng)為自然數(shù)n的n次方的的和或積的級(jí)數(shù),求和或積的表達(dá)式。2009-09-09
教你用vbs實(shí)現(xiàn)微信自動(dòng)發(fā)送消息功能
無意中接觸了vbs這個(gè)腳本感覺挺好玩的,這篇文章主要給大家介紹了關(guān)于如何用vbs實(shí)現(xiàn)微信自動(dòng)發(fā)送消息功能的相關(guān)資料,文中通過實(shí)例代碼介紹的非常詳細(xì),需要的朋友可以參考下2022-04-04
VBScript Enun Remote CMD Shell代碼
Enun Remote CMDShell,喜歡玩cmdshell的朋友可以參考下2013-07-07
一些經(jīng)典的主要用戶黑客的vbs腳本結(jié)合echo的dos下實(shí)現(xiàn)
一些經(jīng)典的主要用戶黑客的vbs腳本結(jié)合echo的dos下實(shí)現(xiàn)...2007-02-02
用vbs實(shí)現(xiàn)將剪切板的unix格式的內(nèi)容處理成pc格式的代碼
用vbs實(shí)現(xiàn)將剪切板的unix格式的內(nèi)容處理成pc格式的代碼...2007-10-10

