Hi @ll, yesterday Microsoft published the security advisory 3004375 <https://technet.microsoft.com/en-us/library/security/3004375> announcing an update which enables Windows 7 and newer to log the command lines used to start processes to the event log.
If you want to have this functionality on older versions of Windows too see <http://home.arcor.de/skanthak/appinit.html> (but notice the license terms). Limitation: command lines of processes that dont load USER32.DLL are not logged. Fortunately almost all Win32 applications but load USER32.DLL JFTR: APPINIT.DLL works since 20 years. regards Stefan Kanthak _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/