Slackbot
03/03/2023, 10:05 AMNick Panaccio
03/03/2023, 11:32 AMJames Rankin
03/03/2023, 11:42 AMNick Panaccio
03/03/2023, 11:42 AMNick Panaccio
03/03/2023, 11:42 AMJames Rankin
03/03/2023, 11:43 AMNick Panaccio
03/03/2023, 11:44 AMNick Panaccio
03/03/2023, 11:45 AMInvoke-Command -cn Hostname -scriptblock {auditpol /set /subcategory:"Logon" /success:enable}
Invoke-Command -cn Hostname -scriptblock {auditpol /set /subcategory:"Process Creation" /success:enable /failure:enable}
Invoke-Command -cn Hostname -scriptblock {auditpol /set /subcategory:"Process Termination" /success:enable /failure:enable}
3. Logon to that VDA with your normal account
4. Run the following to execute the script (elevated):
powershell -executionpolicy bypass -file ".\AnalyzeLogonDuration.ps1" domain\username
Nick Panaccio
03/03/2023, 11:45 AMNick Panaccio
03/03/2023, 11:45 AMJames Rankin
03/03/2023, 12:00 PMNick Panaccio
03/03/2023, 12:01 PMJames Rankin
03/03/2023, 12:09 PMJames Rankin
03/03/2023, 12:21 PMNick Panaccio
03/03/2023, 12:35 PMJames Rankin
03/03/2023, 12:46 PMSpencer Sun
03/03/2023, 1:54 PMSpencer Sun
03/03/2023, 1:55 PMJames Rankin
03/03/2023, 1:55 PMSpencer Sun
03/03/2023, 1:56 PMSpencer Sun
03/03/2023, 2:09 PM